Ruby Grape is a lightweight API framework for Ruby that enables developers to build RESTful web services, with its vulnerability surface centered on the single grape gem. The durable exposure signal around this framework stems from its role in processing web requests and API parameters, typical of application-level frameworks where input validation and protocol-handling issues can arise. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ruby Grape over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3769MEDIUM ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter. | Jul 5, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ruby Grape.
Media articles that mention a CVE ID that affects a product developed by Ruby Grape — matched by CVE ID, not by vendor name.