Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

0
Medium
Published: 07/21/2026 (07/21/2026, 22:05:28 UTC)
Source: GCVE Database
Product: rails-html-sanitizer

Description

A possible cross-site scripting (XSS) vulnerability exists in rails-html-sanitizer versions 1.0.3 through before 1.7.1 when configured to allow certain SVG reference elements such as <use> or <feImage>. The vulnerability arises because the sanitizer restricts local references only on the xlink:href attribute but not on the plain href attribute, which browsers accept per the SVG 2 specification. This can allow external SVG content or images to be loaded and potentially execute scripts in the context of the sanitized document. Applications using the default sanitizer configuration are not affected because these SVG elements are not allowed by default.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Active
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
Low
Subsq. Integrity
Low
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected software

RubyGemsghsa
rails-html-sanitizer
Affected versions
>=1.0.3 <1.7.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/22/2026, 00:37:23 UTC

Technical Analysis

The rails-html-sanitizer library has a vulnerability in versions >=1.0.3 and <1.7.1 related to its handling of SVG reference elements when the sanitizer is configured to allow them. The PermitScrubber restricts local references only on the xlink:href attribute but not on the href attribute, enabling external references via SVG <use> or <feImage> elements. This can lead to cross-site scripting if the referenced SVG document is same-origin and contains scripts. The default sanitizer configuration does not include these SVG elements, so only applications that override allowed tags to include them are affected. The issue was fixed in version 1.7.1.

Potential Impact

If an application overrides the default allowed tags to include SVG reference elements like <use> or <feImage>, an attacker could exploit this to load external SVG content or images. This may lead to execution of scripts in the context of the sanitized document (XSS) or tracking via external images. Applications using default configurations are not impacted. There are no known exploits in the wild.

Mitigation Recommendations

Upgrade rails-html-sanitizer to version 1.7.1 or later where this issue is fixed. Alternatively, do not override the default allowed tags to include SVG reference elements such as <use> or <feImage>. Applications using the default sanitizer configuration are not affected and require no action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-cj75-f6xr-r4g7
Osv Schema Version
1.4.0
Aliases
[]
Ecosystems
["RubyGems"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6a600a9d9c2644c7f8fdeec1

Added to database: 07/22/2026, 00:11:09 UTC

Last enriched: 07/22/2026, 00:37:23 UTC

Last updated: 07/22/2026, 00:37:23 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses