CVE-2024-32464 Overview
CVE-2024-32464 is a cross-site scripting (XSS) vulnerability in Action Text, the rich text component shipped with Ruby on Rails. Instances of ActionText::Attachable::ContentAttachment embedded within a rich_text_area tag could render unsanitized HTML. An attacker who can influence the content of a rich text attachment may inject arbitrary HTML or JavaScript into the Trix editor view. The issue is tracked as [CWE-79] and is fixed in Rails 7.1.3.4 and 7.2.0.beta2.
Critical Impact
Unsanitized HTML inside ContentAttachment instances can execute attacker-controlled script in the context of users viewing or editing rich text content.
Affected Products
- Ruby on Rails versions prior to 7.1.3.4
- Ruby on Rails 7.2.0.beta1
- Applications using Action Text with rich_text_area and ContentAttachment
Discovery Timeline
- 2024-06-04 - CVE-2024-32464 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-32464
Vulnerability Analysis
Action Text brings rich text content and editing to Rails using the Trix editor. The library renders content stored as HTML fragments, mixing user-provided markup with embedded attachments. When an ActionText::Attachable::ContentAttachment is included inside a rich_text_area tag, the attachment's HTML was passed through to the view without being routed through the Action Text sanitizer. An attacker able to persist a crafted attachment payload could cause script execution in any browser that renders the editor view, enabling session theft, UI redress, and actions performed on behalf of the authenticated user.
Root Cause
The ActionText::Content class included Rendering and Serialization, but not the helpers responsible for sanitizing attachment markup. As a result, ContentAttachment HTML bypassed the allow-list applied to normal Action Text content and reached the Trix edit view intact.
Attack Vector
Exploitation requires user interaction, such as viewing or editing a record containing an attacker-supplied rich text attachment. No authentication to the target application is strictly required when attachment content can be influenced from untrusted input (for example, through a comment, review, or document body).
# Security patch: actiontext/app/helpers/action_text/content_helper.rb
sanitize_action_text_content(render_action_text_attachments(content))
end
+ def sanitize_content_attachment(content_attachment)
+ sanitizer.sanitize(
+ content_attachment,
+ tags: sanitizer_allowed_tags,
+ attributes: sanitizer_allowed_attributes,
+ scrubber: scrubber,
+ )
+ end
+
def sanitize_action_text_content(content)
sanitizer.sanitize(
content.to_html,
Source: rails/rails commit e215bf3
# Security patch: actiontext/lib/action_text/content.rb
# body.to_s # => "<h1>Funny times!</h1>"
# body.to_plain_text # => "Funny times!"
class Content
- include Rendering, Serialization
+ include Rendering, Serialization, ContentHelper
Source: rails/rails commit e215bf3
The fix mixes ContentHelper into ActionText::Content and adds sanitize_content_attachment, applying the same allow-list sanitizer used for standard Action Text output.
Detection Methods for CVE-2024-32464
Indicators of Compromise
- Stored rich text records containing <script> tags, on* event handlers, or javascript: URLs inside action_text_rich_texts rows.
- Unexpected ContentAttachment payloads with HTML elements outside the Action Text allow-list such as <iframe>, <object>, or inline SVG with scripting.
- Outbound requests from browsers rendering admin or author views to attacker-controlled domains shortly after editing records.
Detection Strategies
- Audit the action_text_rich_texts table for payloads containing script-capable markup within action-text-attachment elements.
- Review web server logs for POST requests to endpoints handling rich text content with suspiciously large or binary attachment payloads.
- Instrument the Trix edit view with a strict Content Security Policy and alert on CSP violation reports.
Monitoring Recommendations
- Monitor for anomalous session activity following rich text edits, including token reuse from new IP addresses.
- Track Rails application logs for sanitization warnings or ActionText deprecation messages after upgrading.
- Enable browser error and CSP reporting to surface injected content attempts in production.
How to Mitigate CVE-2024-32464
Immediate Actions Required
- Upgrade Rails to 7.1.3.4 or 7.2.0.beta2 or later across all applications using Action Text.
- Rebuild and redeploy container images and dependency lockfiles (Gemfile.lock) so the patched gem versions are actually loaded.
- Review existing rich text records for malicious attachment payloads and sanitize or purge affected rows.
Patch Information
The fix is delivered in commit e215bf3 and documented in GitHub Security Advisory GHSA-prjp-h48f-jgf6. Upgrade to Action Text shipped with Rails 7.1.3.4 or 7.2.0.beta2.
Workarounds
- Restrict which users can create or edit rich text content containing attachments until the upgrade is applied.
- Enforce a strict Content Security Policy that blocks inline scripts and untrusted sources on views rendering Action Text output.
- Server-side scrub ContentAttachment HTML through Rails::Html::SafeListSanitizer before persistence as a defense-in-depth control.
# Upgrade Rails to a patched version
bundle update rails --conservative
# Verify the installed Action Text version
bundle info actiontext | grep -i version
# Confirm the patched release is in use (expect >= 7.1.3.4)
ruby -e "require 'rails'; puts Rails.version"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.