Rails Action Pack是美国Rails团队的一个web框架。提供了路由机制(将请求URL映射到动作),定义实现动作的控制器以及通过渲染视图(各种格式的模板)生成响应的机制。 Rails Action Pack 8.1.2.1之前版本存在跨站脚本漏洞,该漏洞源于调试异常页面未正确转义异常消息,可能导致精心构造的异常消息注入任意HTML和JavaScript,造成跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rails | actionpack | >= 8.1.0, < 8.1.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33195 | 8.0 HIGH | Rails Active Storage has possible Path Traversal in DiskService |
| CVE-2026-33168 | Rails has a possible XSS vulnerability in its Action View tag helpers | |
| CVE-2026-33170 | Rails Active Support has a possible XSS vulnerability in SafeBuffer#% | |
| CVE-2026-33176 | Rails Active Support has a possible DoS vulnerability in its number helpers | |
| CVE-2026-33173 | Rails Active Storage has possible content type bypass via metadata in direct uploads | |
| CVE-2026-33174 | Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range request | |
| CVE-2026-33169 | Rails Active Support has a possible ReDoS vulnerability in number_to_delimited | |
| CVE-2026-33202 | Rails Active Storage has possible glob injection in its DiskService |
No comments yet