# Rails Sanitizer Flaw Enables Remote XSS

Published: 2026-07-16 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/5223574e-ec5d-5ee6-8976-9ab3b8ccf1b8/rails-sanitizer-flaw-enables-remote-xss

> A cross-site scripting vulnerability in Ruby on Rails versions before 1.7.1 lets attackers inject malicious code under certain sanitizer configurations.

ANSSI (CERT-FR) issued an advisory for a cross-site scripting (XSS) vulnerability affecting Ruby on Rails versions prior to 1.7.1. The flaw resides in the rails-html-sanitizer component and allows an attacker to perform indirect remote code injection under specific configurations, potentially leading to script execution in the context of a victim's browser session.

No evidence of active exploitation is mentioned in the advisory. Administrators are advised to consult the official Ruby on Rails security bulletin (GHSA-cj75-f6xr-r4g7) and apply available patches to remediate the vulnerability.

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0891

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5223574e-ec5d-5ee6-8976-9ab3b8ccf1b8/rails-sanitizer-flaw-enables-remote-xss.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
