A vulnerability described as problematic has been identified in phoenixframework phoenix_live_view up to 1.2.8. Affected by this vulnerability is the function validate_local_url of the file lib/phoenix_live_view.ex of the component Redirect Validation. The manipulation of the argument to results in open redirect.

This vulnerability is known as CVE-2026-64941. It is possible to launch the attack remotely. No exploit is available.