HIGH 7.5 RubyGems

Sanitize vulnerable to Improper Input Validation and Cross-site Scripting

GHSA-7f42-p84j-f58p · CVE-2018-3740

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

When Sanitize <= 4.6.2 is used in combination with libxml2 >= 2.9.2, a specially crafted HTML fragment can cause libxml2 to generate improperly escaped output, allowing non-whitelisted attributes to be used on whitelisted elements.

This can allow HTML and JavaScript injection, which could result in XSS if Sanitize's output is served to browsers.

Ready to move

Start Securing

Free, no credit card | First findings in minutes