GHSA-cj75-f6xr-r4g7

    Dashboard / Vulnerabilities / GHSA-cj75-f6xr-r4g7

    GHSA-cj75-f6xr-r4g7

    Published: 21 Jul 2026Last Modified: 10 Sept 2026

    Summary: Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

    Details: ## Summary There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as `<use>`. See related [GHSA-9wjq-cp2p-hrgf](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) in Loofah, whose SVG local-reference logic rails-html-sanitizer mirrors. - Versions affected: `>= 1.0.3, < 1.7.1` - Not affected: `< 1.0.3` - Fixed versions: `1.7.1` ## Impact `Rails::HTML::PermitScrubber` restricts SVG reference elements in the `SVG_ALLOW_LOCAL_HREF` collection to local, same-document references, but that restriction covered only the `xlink:href` attribute. Browsers also accept a plain `href` attribute per the SVG 2 spec, and it was not restricted, so those elements could reference arbitrary external documents. SVG `<use>` can load and render external SVG content by reference, and if the referenced document is same-origin and contains scripts, it could execute in the context of the sanitized document. `<feImage>` can load external images, which can be used for tracking. Applications are impacted only when the allowed tags are overridden to include one of these SVG reference elements, for example `<use>` or `<feImage>`. The default allowed tags do not include these SVG elements, so applications using the default configuration are not affected. ## Workarounds Remove the SVG reference elements (such as `use` and `feImage`) from the overridden allowed tags. Applications using the default allowed tags are not affected. ## References - [GHSA-9wjq-cp2p-hrgf: SVG `href` attribute bypasses local-reference restriction in Loofah](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) - [CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')](https://cwe.mitre.org/data/definitions/79.html) ## Credit Found by maintainer Mike Dalessio during a security audit.

    Affected packages

    Package

    Name: rails-html-sanitizer

    Purl: pkg:gem/rails-html-sanitizer

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 1.0.3
    Fixed -1.7.1

    Affected versions

    1.0.3
    1.0.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-cj75-f6xr-r4g7 | CVE-DB