valid_destination!/2 of the file lib/phoenix_live_view/utils.ex of the component URL Scheme Validator. Such manipulation of the argument URL leads to cross site scripting.
This vulnerability is documented as CVE-2026-58228. The attack can be executed remotely. There is not any exploit available.
Intelligence View
SOCIAL SHARE CARD GENERATOR