Stored XSS vulnerability
Published: July 27, 2026
SECURITY IDENTIFIERS
- GHSA: GHSA-m5f6-4589-m89f
- Vendor Advisory: https://github.com/ankane/blazer/security/advisories/GHSA-m5f6-4589-m89f
GEM
SEVERITY
CVSS v3.x: 5.4 (Medium)
UNAFFECTED VERSIONS
< 1.7.3
PATCHED VERSIONS
>= 3.5.0
DESCRIPTION
An authenticated user can create a malicious query that executes arbitrary JavaScript when another user tries to edit the query. This can be used to perform actions as the other user for resources on the same origin.
