CVE-2026-33170 is a Cross-Site Scripting (XSS) vulnerability affecting Active Support in Ruby on Rails versions prior to 8.1.2.1, 8.0.4.1, and 7.2.3.1. The flaw allows for XSS by incorrectly reporting HTML safety when `SafeBuffer#%` fails to propagate the unsafe flag after in-place mutation with untrusted input, bypassing ERB auto-escaping. Rated Medium severity with a CVSS score of 6.1, it has a network attack vector and low complexity but requires user interaction for exploitation. Currently, there is no evidence of active exploitation, public exploit code, or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2.3.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.0.4.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 8.1.0, < 8.1.2.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.