The unescaped ERB output tag renders content without HTML escaping and can inject attacker markup.
Use the escaping ERB tag and only bypass escaping for content you fully control.