CVE-2026-47068: Phoenix Pubsub Arbitrary Broadcast
Broadcasting to a PubSub topic directly constructed from unverified user input allows an attacker to inject messages into arbitrary or private topics, potentially leading to cross-session interaction, unauthorized state modification, or session hijacking. Validate the topic using `Phoenix.Token.verify/4` or check ownership against the current authenticated s
greprules fetch cve-2026-47068-phoenix-pubsub-arbitrary-broadcast --engine opengrepDescription
Broadcasting to a PubSub topic directly constructed from unverified user input allows an attacker to inject messages into arbitrary or private topics, potentially leading to cross-session interaction, unauthorized state modification, or session hijacking. Validate the topic using `Phoenix.Token.verify/4` or check ownership against the current authenticated s
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.