VORANT. Threat Intelligence Sign in Get the full feed

Rails Sanitizer Flaw Enables Remote XSS

medium vulnerability technology

A cross-site scripting vulnerability in Ruby on Rails versions before 1.7.1 lets attackers inject malicious code under certain sanitizer configurations.

ANSSI (CERT-FR) issued an advisory for a cross-site scripting (XSS) vulnerability affecting Ruby on Rails versions prior to 1.7.1. The flaw resides in the rails-html-sanitizer component and allows an attacker to perform indirect remote code injection under specific configurations, potentially leading to script execution in the context of a victim's browser session.

No evidence of active exploitation is mentioned in the advisory. Administrators are advised to consult the official Ruby on Rails security bulletin (GHSA-cj75-f6xr-r4g7) and apply available patches to remediate the vulnerability.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0891

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free