Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2021-30151Cross-site Scripting in Sidekiq

Severity
6.1MEDIUMNVD
EPSS
23.9%
top 3.96%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 6
Latest updateAug 14

Description

Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explorer is used.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

RubyGemscontribsys/sidekiq6.0.06.2.1+1
debiandebian/ruby-sidekiq< ruby-sidekiq 6.3.1+dfsg-1 (bookworm)
NVDcontribsys/sidekiq6.0.06.2.0+1

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

4
OSV
ruby-sidekiq vulnerabilities2025-08-14
OSV
Cross-site Scripting in Sidekiq2021-10-06
GHSA
Cross-site Scripting in Sidekiq2021-10-06
OSV
CVE-2021-30151: Sidekiq through 52021-04-06

💥Exploits & PoCs

1
Nuclei
Sidekiq <=6.2.0 - Cross-Site Scripting

📋Vendor Advisories

3
Ubuntu
Sidekiq vulnerabilities2025-08-14
Red Hat
sidekiq: XSS via the queue name of the live-poll feature2021-10-08
Debian
CVE-2021-30151: ruby-sidekiq - Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the...2021