Security readout for executives and security teams
Plain-English summary
CVE-2022-23518 affects Rails applications that rely on rails-html-sanitizer to clean user-controlled HTML. In vulnerable dependency combinations, data URIs were not neutralized correctly, creating a cross-site scripting risk. A successful attack could expose or alter browser-visible data for an interacting user, but sources do not show active exploitation.
Executive priority
Treat this as a moderate web application risk. It is not a broad infrastructure emergency, but internet-facing Rails applications with rich-text user content should be patched promptly because XSS can affect user trust, sessions, and data integrity.
Technical view
rails-html-sanitizer versions >= 1.0.3 and < 1.4.4 are vulnerable when used with Loofah >= 2.1.0. The issue is CWE-79 improper neutralization, enabling XSS through data URIs in sanitized HTML fragments. CVSS 3.0 is 6.1: network reachable, low complexity, no privileges, user interaction required, changed scope, low confidentiality and integrity impact.
Likely exposure
Exposure is most likely in Rails applications that accept or store user-supplied HTML, sanitize it with rails-html-sanitizer, and render it back to users while running the affected gem versions with Loofah >= 2.1.0.
Exploitation context
The CVE is not listed as KEV in the supplied data, and the source bundle does not establish active exploitation. Exploitation requires user interaction and a code path where untrusted HTML is sanitized then displayed in a browser.
Researcher notes
Key evidence is the GitHub security advisory, CVE record, GitHub issue, and HackerOne report. The supplied data gives exact affected and fixed versions, but does not prove exploit-in-the-wild activity or identify additional affected products beyond rails-html-sanitizer and the Loofah dependency condition.
Mitigation direction
- Upgrade rails-html-sanitizer to version 1.4.4 or later.
- Review dependency resolution for Loofah >= 2.1.0 with affected sanitizer versions.
- For Debian-packaged deployments, review and apply relevant Debian LTS updates.
- Prioritize applications rendering user-submitted rich text or HTML.
- Check current vendor guidance before relying on alternate mitigations.
Validation and detection
- Inventory Gemfile.lock and package manifests for rails-html-sanitizer versions.
- Confirm whether Loofah >= 2.1.0 is present in affected applications.
- Map routes and views that sanitize and render untrusted HTML.
- Verify production runtime uses rails-html-sanitizer 1.4.4 or later.
- Add regression tests for sanitized user HTML rendering paths.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2022-23518 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.1 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N2.82.7Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
6.1MediumVector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/rails/rails-html-sanitizer/security/advisories/GHSA-mcvf-2q2m-x72mCVE reference · x_refsource_CONFIRM
- https://github.com/rails/rails-html-sanitizer/issues/135CVE reference · x_refsource_MISC
- https://hackerone.com/reports/1694173CVE reference · x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2023/09/msg00012.htmlCVE reference
- https://lists.debian.org/debian-lts-announce/2024/09/msg00045.htmlCVE reference
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
