216.73.217.22

CVE-2026-33167

· Published 23/03/2026 23:17 · Modified 24/03/2026 15:53

Labels: CVE-2026-33167 2026-03-23CVE-2026-33167CWE-79[email protected]

Essential information

Published
23/03/2026 23:17
Modified
24/03/2026 15:53
Author
Creator
CVSS
1.3 LOW (v3) 1.3 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ruby / action pack cpe:2.3:a:ruby:action_pack:<8.1.2.1:*:*:*:*:*:*
ruby / rails cpe:2.3:a:ruby:rails:8.1:*:*:*:*:*:*

References