Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
A possible cross-site scripting (XSS) vulnerability exists in rails-html-sanitizer versions 1.0.3 through before 1.7.1 when configured to allow certain SVG reference elements such as <use> or <feImage>. The vulnerability arises because the sanitizer restricts local references only on the xlink:href attribute but not on the plain href attribute, which browsers accept per the SVG 2 specification. This can allow external SVG content or images to be loaded and potentially execute scripts in the context of the sanitized document. Applications using the default sanitizer configuration are not affected because these SVG elements are not allowed by default.
AI Analysis
Technical Summary
The rails-html-sanitizer library has a vulnerability in versions >=1.0.3 and <1.7.1 related to its handling of SVG reference elements when the sanitizer is configured to allow them. The PermitScrubber restricts local references only on the xlink:href attribute but not on the href attribute, enabling external references via SVG <use> or <feImage> elements. This can lead to cross-site scripting if the referenced SVG document is same-origin and contains scripts. The default sanitizer configuration does not include these SVG elements, so only applications that override allowed tags to include them are affected. The issue was fixed in version 1.7.1.
Potential Impact
If an application overrides the default allowed tags to include SVG reference elements like <use> or <feImage>, an attacker could exploit this to load external SVG content or images. This may lead to execution of scripts in the context of the sanitized document (XSS) or tracking via external images. Applications using default configurations are not impacted. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade rails-html-sanitizer to version 1.7.1 or later where this issue is fixed. Alternatively, do not override the default allowed tags to include SVG reference elements such as <use> or <feImage>. Applications using the default sanitizer configuration are not affected and require no action.
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Description
A possible cross-site scripting (XSS) vulnerability exists in rails-html-sanitizer versions 1.0.3 through before 1.7.1 when configured to allow certain SVG reference elements such as <use> or <feImage>. The vulnerability arises because the sanitizer restricts local references only on the xlink:href attribute but not on the plain href attribute, which browsers accept per the SVG 2 specification. This can allow external SVG content or images to be loaded and potentially execute scripts in the context of the sanitized document. Applications using the default sanitizer configuration are not affected because these SVG elements are not allowed by default.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The rails-html-sanitizer library has a vulnerability in versions >=1.0.3 and <1.7.1 related to its handling of SVG reference elements when the sanitizer is configured to allow them. The PermitScrubber restricts local references only on the xlink:href attribute but not on the href attribute, enabling external references via SVG <use> or <feImage> elements. This can lead to cross-site scripting if the referenced SVG document is same-origin and contains scripts. The default sanitizer configuration does not include these SVG elements, so only applications that override allowed tags to include them are affected. The issue was fixed in version 1.7.1.
Potential Impact
If an application overrides the default allowed tags to include SVG reference elements like <use> or <feImage>, an attacker could exploit this to load external SVG content or images. This may lead to execution of scripts in the context of the sanitized document (XSS) or tracking via external images. Applications using default configurations are not impacted. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade rails-html-sanitizer to version 1.7.1 or later where this issue is fixed. Alternatively, do not override the default allowed tags to include SVG reference elements such as <use> or <feImage>. Applications using the default sanitizer configuration are not affected and require no action.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cj75-f6xr-r4g7
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["RubyGems"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a600a9d9c2644c7f8fdeec1
Added to database: 07/22/2026, 00:11:09 UTC
Last enriched: 07/22/2026, 00:37:23 UTC
Last updated: 07/22/2026, 00:37:23 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.