4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether phlex is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.1
CVE-2024-32970
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
HIGH 7.1
CVE-2024-32463
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
HIGH 7.1
CVE-2024-28199
Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex
HIGH 7.1
GHSA-w67g-2h6v-vjgq
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
Browse more RubyGems advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes