Use render html: instead of inline:
cantino opened this issue · comments
Andrew Cantino commented
By using render inline:
here you may be introducing a RCE since it will evaluate ERB.
Is that intended?
Gleb Mazovetskiy commented
Good catch!
Gleb Mazovetskiy commented
Fixed, released in https://github.com/glebm/rails_email_preview/releases/tag/v2.2.2
Andrew Cantino commented
👍