Stimulusreflex is a JavaScript library for reactive updates in Rails applications that bridges client-side and server-side code execution through reflection-based method invocation. The library's documented vulnerability pattern centers on unsafe reflection—specifically the use of externally-controlled input to select or invoke classes and methods—a weakness class inherent to its design approach that defenders should account for when evaluating the security posture of applications that depend on it. Current exploitation activity, severity ratings, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stimulusreflex over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28121HIGH stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and passing them to Rails over real-time websockets. In affected | Mar 12, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stimulusreflex.
Media articles that mention a CVE ID that affects a product developed by Stimulusreflex — matched by CVE ID, not by vendor name.