Medium severity6.1NVD Advisory· Published Dec 2, 2024· Updated Jun 17, 2026
CVE-2024-53987
CVE-2024-53987
Description
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an attacker to inject content if HTML5 sanitization is enabled and the application developer has overridden the sanitizer's allowed tags where the "style" element is explicitly allowed and the "svg" or "math" element is not allowed. This vulnerability is fixed in 1.6.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rails-html-sanitizerRubyGems | >= 1.6.0, < 1.6.1 | 1.6.1 |
Affected products
4- cpe:2.3:a:rubyonrails:rails_html_sanitizers:1.6.0:*:*:*:*:rails:*:*
- ghsa-coords2 versionspkg:gem/rails-html-sanitizerpkg:rpm/opensuse/rubygem-rails-html-sanitizer&distro=openSUSE%20Tumbleweed
>= 1.6.0, < 1.6.1+ 1 more
- (no CPE)range: >= 1.6.0, < 1.6.1
- (no CPE)range: < 1.7.0-1.1
- Range: >= 1.6.0, < 1.6.1
Patches
Vulnerability mechanics
References
5- github.com/rails/rails-html-sanitizer/commit/f02ffbb8465e73920b6de0da940f5530f855965envdPatchWEB
- github.com/advisories/GHSA-2x5m-9ch4-qgrrghsaADVISORY
- github.com/rails/rails-html-sanitizer/security/advisories/GHSA-2x5m-9ch4-qgrrnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-53987ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/rails-html-sanitizer/CVE-2024-53987.ymlghsaWEB
News mentions
0No linked articles in our index yet.