CVE-2026-33167

EPSS 0.02%

Rails has a possible XSS vulnerability in its Action Pack debug exceptions

Published: 3/23/2026Modified: 5/13/2026
Also known as:GHSA-pgm4-439c-5jp6CGA-c97h-38xv-957r

Description

### Impact The debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. ### Releases The fixed releases are available at the normal locations. ### Credit This issue was responsibly reported by Hackerone researcher [fbettag](https://hackerone.com/fbettag).

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U

References (6)