{"apiVersion":"1.0","identifier":"CVE-2026-66353","description":"Improper Neutralization of Input During Web Page Generation (-Cross-site Scripting-) vulnerability in woylie doggo allows Reflected XSS. Doggo.normalize_value/2 in lib/doggo.ex returned date field values wrapped in {:safe, ...}, the Phoenix.HTML marker meaning -already escaped, emit verbatim-, without escaping them, so the value reached the value attribute of the <input> rendered by the field component unchanged. Any application rendering <.field type=-date-> over user-controlled params is affected through the ordinary Phoenix form round-trip, where a failed validation re-renders the submitted value. The pattern kept exactly the first ten bytes and discarded shorter values, capping a payload at ten bytes: enough to terminate the attribute and open an element or attach a short event handler, not enough to place attacker-chosen script inline. Only type=-date- is affected. This issue affects doggo: from 0.1.0 before 0.14.8.","publishedAt":"2026-08-27T20:18:27","lastModifiedAt":"2026-08-28T16:18:20","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66353","cvssScore":5.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","epssProbability":0.00394,"riskScore":0.55,"affectedProduct":"doggo","affectedVersions":">=0.1.0,<0.14.8","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-66353","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-66353","en":"https://www.redsauce.net/en/cves/CVE-2026-66353","fr":"https://www.redsauce.net/fr/cves/CVE-2026-66353","pt":"https://www.redsauce.net/pt/cves/CVE-2026-66353","de":"https://www.redsauce.net/de/cves/CVE-2026-66353","sk":"https://www.redsauce.net/sk/cves/CVE-2026-66353","el":"https://www.redsauce.net/el/cves/CVE-2026-66353"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-66353"}}