PT-2026-27254 · Rubygems+1 · Action Pack+1
John Hawthorn
·
Published
2026-03-23
·
Updated
2026-03-24
·
CVE-2026-33167
CVSS v4.0
1.3
Low
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
Action Pack versions prior to 8.1.2.1
Description
Action Pack, a Rubygem for building web applications on the Rails framework, has an issue where the debug exceptions page does not properly escape exception messages. A crafted exception message could inject arbitrary HTML and JavaScript into the page, potentially leading to Cross-Site Scripting (XSS). This impacts applications with detailed exception pages enabled (
config.consider all requests local = true), which is the default in development.Recommendations
Update to Action Pack version 8.1.2.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Action Pack
Rails