ghsa-cj75-f6xr-r4g7

CVSS 5.1 osv_rubygems
Description

## Summary There is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as `<use>`. See related [GHSA-9wjq-cp2p-hrgf](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) in Loofah, whose SVG local-reference logic rails-html-sanitizer mirrors. - Versions affected: `>= 1.0.3, < 1.7.1` - Not affected: `< 1.0.3` - Fixed versions: `1.7.1` ## Impact `Rails::HTML::PermitScrubber` restricts SVG reference elements in the `SVG_ALLOW_LOCAL_HREF` collection to local, same-document references, but that restriction covered only the `xlink:href` attribute. Browsers also accept a plain `href` attribute per the SVG 2 spec, and it was not restricted, so those elements could reference arbitrary external documents. SVG `<use>` can load and render external SVG content by reference, and if the referenced document is same-origin and contains scripts, it could execute in the context of the sanitized document. `<feImage>` can load external images, which can be used for tracking. Applications are impacted only when the allowed tags are overridden to include one of these SVG reference elements, for example `<use>` or `<feImage>`. The default allowed tags do not include these SVG elements, so applications using the default configuration are not affected. ## Workarounds Remove the SVG reference elements (such as `use` and `feImage`) from the overridden allowed tags. Applications using the default allowed tags are not affected. ## References - [GHSA-9wjq-cp2p-hrgf: SVG `href` attribute bypasses local-reference restriction in Loofah](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) - [CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')](https://cwe.mitre.org/data/definitions/79.html) ## Credit Found by maintainer Mike Dalessio during a security audit.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-cj75-f6xr-r4g7/GHSA-cj75-f6xr-r4g7.json"
      },
      "package": {
        "ecosystem": "RubyGems",
        "name": "rails-html-sanitizer",
        "purl": "pkg:gem/rails-html-sanitizer"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "1.0.3"
            },
            {
              "fixed": "1.7.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "1.0.3",
        "1.0.4",
        "1.1.0",
        "1.2.0",
        "1.3.0",
        "1.4.0",
        "1.4.1",
        "1.4.2",
        "1.4.3",
        "1.4.4",
        "1.5.0",
        "1.6.0",
        "1.6.0.rc1",
        "1.6.0.rc2",
        "1.6.1",
        "1.6.2",
        "1.7.0"
      ]
    }
  ],
  "aliases": [
    "CVE-2026-73648"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-21T22:05:28Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "## Summary\n\nThere is a possible cross-site scripting vulnerability in rails-html-sanitizer when the sanitizer is configured to allow an SVG reference element such as `<use>`. See related [GHSA-9wjq-cp2p-hrgf](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf) in Loofah, whose SVG local-reference logic rails-html-sanitizer mirrors.\n\n- Versions affected: `>= 1.0.3, < 1.7.1`\n- Not affected: `< 1.0.3`\n- Fixed versions: `1.7.1`\n\n## Impact\n\n`Rails::HTML::PermitScrubber` restricts SVG reference elements in the `SVG_ALLOW_LOCAL_HREF` collection to local, same-document references, but that restriction covered only the `xlink:href` attribute. Browsers also accept a plain `href` attribute per the SVG 2 spec, and it was not restricted, so those elements could reference arbitrary external documents. SVG `<use>` can load and render external SVG content by reference, and if the referenced document is same-origin and contains scripts, it could execute in the context of the sanitized document. `<feImage>` can load external images, which can be used for tracking.\n\nApplications are impacted only when the allowed tags are overridden to include one of these SVG reference elements, for example `<use>` or `<feImage>`. The default allowed tags do not include these SVG elements, so applications using the default configuration are not affected.\n\n## Workarounds\n\nRemove the SVG reference elements (such as `use` and `feImage`) from the overridden allowed tags. Applications using the default allowed tags are not affected.\n\n## References\n\n- [GHSA-9wjq-cp2p-hrgf: SVG `href` attribute bypasses local-reference restriction in Loofah](https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf)\n- [CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')](https://cwe.mitre.org/data/definitions/79.html)\n\n## Credit\n\nFound by maintainer Mike Dalessio during a security audit.",
  "id": "GHSA-cj75-f6xr-r4g7",
  "modified": "2026-09-10T03:51:11.467365597Z",
  "published": "2026-07-21T22:05:28Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-cj75-f6xr-r4g7"
    },
    {
      "type": "WEB",
      "url": "https://github.com/rails/rails-html-sanitizer/commit/74dcb8053e6da9921246ce71b06ad9fd65b19586"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/rails/rails-html-sanitizer"
    },
    {
      "type": "WEB",
      "url": "https://github.com/rails/rails-html-sanitizer/releases/tag/v1.7.1"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations"
}
View JSON API Download JSON