<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/ghsa-m5f6-4589-m89f-blazer-stored-xss-vulnerability-3ifg1cgjx" -->

---
title: GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability
description: A stored XSS vulnerability (GHSA-m5f6-4589-m89f) has been disclosed in the Blazer Ruby gem. An authenticated user can craft a malicious query that executes...
canonical: https://daily.dev/posts/ghsa-m5f6-4589-m89f-blazer-stored-xss-vulnerability-3ifg1cgjx
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability | daily.dev
og:description: A stored XSS vulnerability (GHSA-m5f6-4589-m89f) has been disclosed in the Blazer Ruby gem. An authenticated user can craft a malicious query that executes...
og:url: https://daily.dev/posts/ghsa-m5f6-4589-m89f-blazer-stored-xss-vulnerability-3ifg1cgjx
og:image: https://api.daily.dev/og/posts/3ifG1Cgjx.png
og:image:alt: GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability

**[RUBYLAND](https://daily.dev/sources/rubyla)** · 1 min read · 0 upvotes · 0 comments

## Summary

A stored XSS vulnerability (GHSA-m5f6-4589-m89f) has been disclosed in the Blazer Ruby gem. An authenticated user can craft a malicious query that executes arbitrary JavaScript when another user attempts to edit it, enabling actions on behalf of that user within the same origin. The vulnerability carries a CVSS v3.x score of 5.4 (Medium). Versions prior to 1.7.3 are unaffected; the fix is available in version 3.5.0 and above.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://rubysec.com/advisories/GHSA-m5f6-4589-m89f>

## Similar posts on daily.dev

- [GHSA-cj75-f6xr-r4g7 \(rails-html-sanitizer\): Possible XSS vulnerability with certain configurations of rails-html-sanitizer](https://daily.dev/posts/ghsa-cj75-f6xr-r4g7-rails-html-sanitizer-possible-xss-vulnerability-with-certain-configurations-o-9lq3cmn5j) · RUBYLAND · 1 upvotes · 0 comments
- [GHSA-qmpg-8xg6-ph5q \(action\_text-trix\): Trix has a Stored XSS vulnerability through serialized attributes](https://daily.dev/posts/ghsa-qmpg-8xg6-ph5q-action-text-trix-trix-has-a-stored-xss-vulnerability-through-serialized-attri-u8bd02ehq) · RUBYLAND · 0 upvotes · 0 comments
- [GHSA-4249-gjr8-jpq3 \(prosemirror\_to\_html\): ProsemirrorToHtml has a Cross-Site Scripting \(XSS\) vulnerability through unescaped HTML attribute values](https://daily.dev/posts/ghsa-4249-gjr8-jpq3-prosemirror-to-html-prosemirrortohtml-has-a-cross-site-scripting-xss-vulner-fyyo8nbti) · RUBYLAND · 0 upvotes · 0 comments
- [GHSA-r827-6rm4-59pg \(alchemy\_cms\): Stored XSS via unsanitized SVG attachment replacement](https://daily.dev/posts/ghsa-r827-6rm4-59pg-alchemy-cms-stored-xss-via-unsanitized-svg-attachment-replacement-pfpoczydp) · RUBYLAND · 1 upvotes · 0 comments

---

Tags: [#ruby](https://daily.dev/tags/ruby)

[View this post on daily.dev](https://daily.dev/posts/ghsa-m5f6-4589-m89f-blazer-stored-xss-vulnerability-3ifg1cgjx)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability","url":"https://daily.dev/posts/ghsa-m5f6-4589-m89f-blazer-stored-xss-vulnerability-3ifg1cgjx","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/ghsa-m5f6-4589-m89f-blazer-stored-xss-vulnerability-3ifg1cgjx"},"datePublished":"2026-07-29T19:23:38.955Z","dateModified":"2026-07-29T19:35:52.258Z","description":"A stored XSS vulnerability (GHSA-m5f6-4589-m89f) has been disclosed in the Blazer Ruby gem. An authenticated user can craft a malicious query that executes...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5fa7bf38a8a9c178c1d458f9f735556c?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/5fa7bf38a8a9c178c1d458f9f735556c?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"RUBYLAND","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"RUBYLAND","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/rubyla","url":"https://daily.dev/sources/rubyla"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/ghsa-m5f6-4589-m89f-blazer-stored-xss-vulnerability-3ifg1cgjx","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ruby","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"RUBYLAND","item":"https://daily.dev/sources/rubyla"},{"@type":"ListItem","position":3,"name":"GHSA-m5f6-4589-m89f (blazer): Stored XSS vulnerability"}]}
```

