A vulnerability labeled as problematic has been found in rails rails-html-sanitizer up to 1.7.0. Affected by this issue is some unknown functionality of the component PermitScrubber. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is reported as CVE-2026-73648. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.