rails Vulnerabilities and Affected Products
Vulnerabilities associated with actionpack.
Products
Clear product- rails14 vulnerabilities
- rails-html-sanitizer11 vulnerabilities
- activestorage6 vulnerabilities
- activesupport5 vulnerabilities
- actionview3 vulnerabilities
- https://github.com/rails/rails3 vulnerabilities
- Ruby on Rails3 vulnerabilities
- Action Pack1 vulnerability
- actionpack1 vulnerability
- Kredis JSON1 vulnerability
- Rack1 vulnerability
- rails-ujs1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Rails has a possible XSS vulnerability in its Action Pack debug exceptionsAction Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch. CWE-79Mar 23, 2026 | CVSS1.3v4.0 | EPSS0.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |