phlex
Build HTML, SVG and CSV views with Ruby classes.
Activity
- Latest release
- 7mo ago
- Total releases
- 75
- Cadence
- ~daily
- Last 12 months
- 7
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jun 03, 2022
| Version | Released | |
|---|---|---|
2.3.2
patch
| ||
1.11.1
patch
| ||
2.2.2
patch
| ||
2.1.3
patch
| ||
2.4.1
patch
| ||
2.0.3
patch
| ||
2.4.0
minor
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.4.0.beta2
pre
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.4.0.beta1
pre
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.3.1
patch
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.1.2
patch
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.0.2
patch
| ||
2.0.1
patch
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.0.0.rc2
pre
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.0.0.rc1
pre
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.0.0.beta2
pre
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
2.0.0.beta1
pre
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
1.11.0
minor
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
1.10.3
patch
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
1.9.3
patch
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
1.10.2
patch
1 CVE
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev | ||
1.8.3
patch
2 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.3
patch
2 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.2
patch
2 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.3
patch
2 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.2
patch
2 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.2
patch
2 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.1
patch
2 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.10.0
minor
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.1
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.2
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.1
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.2
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.8.2
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.1
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.2
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.1
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.1
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.3
patch
3 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.9.0
minor
4 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28199
GHSA-242p-4v39-2v8g
Mar 12, 2024
Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent these attacks. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
1.9.0
1.8.0
1.8.1
1.7.0
1.6.0
1.6.1
1.5.0
1.5.1
1.4.0
1.3.0
1.3.1
1.3.2
+ 18 more Show less
1.2.0
1.2.1
1.1.0
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
Fixed in
1.0.1
1.1.1
1.2.2
1.3.3
1.4.1
1.5.2
1.6.2
1.7.1
1.8.2
1.9.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.8.1
patch
4 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28199
GHSA-242p-4v39-2v8g
Mar 12, 2024
Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent these attacks. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
1.9.0
1.8.0
1.8.1
1.7.0
1.6.0
1.6.1
1.5.0
1.5.1
1.4.0
1.3.0
1.3.1
1.3.2
+ 18 more Show less
1.2.0
1.2.1
1.1.0
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
Fixed in
1.0.1
1.1.1
1.2.2
1.3.3
1.4.1
1.5.2
1.6.2
1.7.1
1.8.2
1.9.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.8.0
minor
4 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28199
GHSA-242p-4v39-2v8g
Mar 12, 2024
Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent these attacks. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
1.9.0
1.8.0
1.8.1
1.7.0
1.6.0
1.6.1
1.5.0
1.5.1
1.4.0
1.3.0
1.3.1
1.3.2
+ 18 more Show less
1.2.0
1.2.1
1.1.0
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
Fixed in
1.0.1
1.1.1
1.2.2
1.3.3
1.4.1
1.5.2
1.6.2
1.7.1
1.8.2
1.9.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.0
minor
4 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28199
GHSA-242p-4v39-2v8g
Mar 12, 2024
Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent these attacks. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
1.9.0
1.8.0
1.8.1
1.7.0
1.6.0
1.6.1
1.5.0
1.5.1
1.4.0
1.3.0
1.3.1
1.3.2
+ 18 more Show less
1.2.0
1.2.1
1.1.0
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
Fixed in
1.0.1
1.1.1
1.2.2
1.3.3
1.4.1
1.5.2
1.6.2
1.7.1
1.8.2
1.9.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.1
patch
4 CVEs
GHSA-w67g-2h6v-vjgq
Feb 06, 2026
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
ImpactDuring a security audit conducted with Claude Opus 4.6 and GPT-5.3-Codex, we identified three specific ways to bypass the XSS (cross-site-scripting) protection built into Phlex.
All three of these patterns are meant to be safe and all have now been patched. PatchesPhlex has patched all three issues and introduced new tests that run against Safari, Firefox and Chrome. The patched versions are: Phlex has also patched the WorkaroundsIf a project uses a secure CSP (content security policy) or if the application doesn’t use any of the above patterns, it is not at risk. Affected versions
2.4.0
2.4.0.beta1
2.4.0.beta2
2.3.0
2.3.1
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.0.0
2.0.0.beta1
+ 56 more Show less
2.0.0.beta2
2.0.0.rc1
2.0.0.rc2
2.0.1
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.10.2
1.10.3
1.11.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.9.3
Fixed in
1.11.1
2.0.2
2.1.3
2.2.2
2.3.2
2.4.1
References
Updated Feb 06, 2026 · Source: OSV.dev
CVE-2024-32970
GHSA-9p57-h987-4vgx
May 01, 2024
Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The reason these issues were not detected before is the escapes were working as designed. However, their design didn't take into account just how recklessly permissive browser are when it comes to executing unsafe JavaScript via HTML attributes. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all minor versions released in the last year. If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
+ 36 more Show less
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
1.10.0
1.10.1
Fixed in
1.9.3
1.10.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-32463
GHSA-g7xq-xv8c-h98c
Apr 17, 2024
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
SummaryThere is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. Our filter to detect and prevent the use of the ImpactIf you render an
MitigationThe best way to mitigate this vulnerability is to update to one of the following versions: WorkaroundsConfiguring a Content Security Policy that does not allow Affected versions
1.10.0
1.9.0
1.9.1
1.8.0
1.8.1
1.8.2
1.7.0
1.7.1
1.6.0
1.6.1
1.6.2
1.5.0
+ 29 more Show less
1.5.1
1.5.2
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
Fixed in
1.4.2
1.5.3
1.6.3
1.7.2
1.8.3
1.9.2
1.10.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-28199
GHSA-242p-4v39-2v8g
Mar 12, 2024
Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent these attacks. ImpactIf you render an
If you splat user-provided attributes when rendering any HTML or SVG tag, malicious event attributes could be included in the output, executing JavaScript when the events are triggered by another user.
PatchesPatches are available on RubyGems for all If you are on WorkaroundsConfiguring a Content Security Policy that does not allow ReferencesIn addition to upgrading to a patched version of Phlex, we strongly recommend configuring a Content Security Policy header that does not allow Affected versions
1.9.0
1.8.0
1.8.1
1.7.0
1.6.0
1.6.1
1.5.0
1.5.1
1.4.0
1.3.0
1.3.1
1.3.2
+ 18 more Show less
1.2.0
1.2.1
1.1.0
0.1.0
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
1.0.0
1.0.0.rc1
1.0.0.rc2
Fixed in
1.0.1
1.1.1
1.2.2
1.3.3
1.4.1
1.5.2
1.6.2
1.7.1
1.8.2
1.9.1
References
Updated Sep 10, 2026 · Source: OSV.dev |