{"id":"GHSA-cj75-f6xr-r4g7","title":"Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations","summary":"Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations","severity":"medium","cwe":["CWE-79"],"vendor":"rails-html-sanitizer","product":"rails-html-sanitizer","ecosystem":"rubygems","affected":["rails-html-sanitizer >= 1.0.3, < 1.7.1"],"patched":["rails-html-sanitizer 1.7.1"],"published":"2026-07-21","updated":"2026-07-21","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-cj75-f6xr-r4g7","references":[{"url":"https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-cj75-f6xr-r4g7"},{"url":"https://github.com/rails/rails-html-sanitizer/commit/74dcb8053e6da9921246ce71b06ad9fd65b19586"},{"url":"https://github.com/rails/rails-html-sanitizer/releases/tag/v1.7.1"},{"url":"https://github.com/advisories/GHSA-cj75-f6xr-r4g7"}],"tags":["ghsa","rubygems"],"ingestedAt":"2026-07-21T22:55:08.449Z","slug":"GHSA-cj75-f6xr-r4g7","body":"## Overview\n\n## Summary\n\nThere is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as `<use>`. See related [GHSA-9wjq-cp2p-hrgf](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) in Loofah, whose SVG local-reference logic rails-html-sanitizer mirrors.\n\n- Versions affected: `>= 1.0.3, < 1.7.1`\n- Not affected: `< 1.0.3`\n- Fixed versions: `1.7.1`\n\n## Impact\n\n`Rails::HTML::PermitScrubber` restricts SVG reference elements in the `SVG_ALLOW_LOCAL_HREF` collection to local, same-document references, but that restriction covered only the `xlink:href` attribute. Browsers also accept a plain `href` attribute per the SVG 2 spec, and it was not restricted, so those elements could reference arbitrary external documents. SVG `<use>` can load and render external SVG content by reference, and if the referenced document is same-origin and contains scripts, it could execute in the context of the sanitized document. `<feImage>` can load external images, which can be used for tracking.\n\nApplications are impacted only when the allowed tags are overridden to include one of these SVG reference elements, for example `<use>` or `<feImage>`. The default allowed tags do not include these SVG elements, so applications using the default configuration are not affected.\n\n## Workarounds\n\nRemove the SVG reference elements (such as `use` and `feImage`) from the overridden allowed tags. Applications using the default allowed tags are not affected.\n\n## References\n\n- [GHSA-9wjq-cp2p-hrgf: SVG `href` attribute bypasses local-reference restriction in Loofah](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf)\n- [CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')](https://cwe.mitre.org/data/definitions/79.html)\n\n## Credit\n\nFound by maintainer Mike Dalessio during a security audit.\n\n## Affected packages\n\n- `rails-html-sanitizer >= 1.0.3, < 1.7.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `rails-html-sanitizer 1.7.1`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}