CVE-2026-33168
CVE-2026-33168 — Rails has a possible XSS vulnerability in its Action View tag helpers
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Published Updated Sources: cvelistV5, GitHub_M
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
1%
chance of exploitation in 30 days
CVSS base
2.3
LOW
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
None
none · proof-of-concept · active
Automatable
No
can an attacker script all four kill-chain steps
Technical impact
Partial
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 2.3 | CVSS 4.0 | LOW | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-79
References
7 on the record
- github.com/rails/rails/security/advisories/GHSA-v55j-83pf-r9cq
x_refsource_CONFIRM
- github.com/rails/rails/commit/0b6f8002b52b9c606fd6be9e7915d9f944cf539c
x_refsource_MISC
- github.com/rails/rails/commit/63f5ad83edaa0b976f82d46988d745426aa4a42d
x_refsource_MISC
- github.com/rails/rails/commit/c79a07df1e88738df8f68cb0ee759ad6128ca924
x_refsource_MISC
- github.com/rails/rails/releases/tag/v7.2.3.1
x_refsource_MISC
- github.com/rails/rails/releases/tag/v8.0.4.1
x_refsource_MISC
- github.com/rails/rails/releases/tag/v8.1.2.1
x_refsource_MISC
Elsewhere on this site
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.