RubySec

Providing security resources for the Ruby community

GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability

Stored XSS vulnerability

Published: July 27, 2026

SECURITY IDENTIFIERS

GEM

blazer

SEVERITY

CVSS v3.x: 5.4 (Medium)

UNAFFECTED VERSIONS

< 1.7.3

PATCHED VERSIONS

>= 3.5.0

DESCRIPTION

An authenticated user can create a malicious query that executes arbitrary JavaScript when another user tries to edit the query. This can be used to perform actions as the other user for resources on the same origin.

RELATED