Cross-Site Scripting Vulnerability in Action Pack for Ruby on Rails
CVE-2026-33167

1.3LOW

Key Information:

Vendor

Rails

Vendor
CVE Published:
23 March 2026

What is CVE-2026-33167?

A vulnerability in Action Pack, a RubyGem for building web applications on Rails, allows for the injection of arbitrary HTML and JavaScript into the debug exceptions page due to inadequate escaping of exception messages. This issue impacts applications where detailed exception pages are enabled (by default in development mode). Attackers can exploit this flaw to perform Cross-Site Scripting (XSS) attacks, potentially compromising the security of web applications. The issue affects versions prior to 8.1.2.1, which contains the necessary patch to mitigate the risk.

Affected Version(s)

actionpack >= 8.1.0, < 8.1.2.1

References

CVSS V4

Score:
1.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.