CVE-2026-33168
published 2026-03-23CVE-2026-33168: Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank…
PriorityP415low2.3CVSS 4.0
AVNACLATPPRNUIPVCLVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.52%
40.5th percentile
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | — | — |
| rails | actionview | < 7.2.3.1 | 7.2.3.1 |
| rails | actionview | — | — |
| rails | actionview | — | — |
| rails | actionview | >= 0 < 7.2.3.1 | 7.2.3.1 |
| rails | actionview | >= 8.0.0.beta1 < 8.0.4.1 | 8.0.4.1 |
| rails | actionview | >= 8.1.0.beta1 < 8.1.2.1 | 8.1.2.1 |
CVSS provenance
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv2.3LOW
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Rails has a possible XSS vulnerability in its Action View tag helpers
ghsa·2026-03-23
CVE-2026-33168 [LOW] CWE-79 Rails has a possible XSS vulnerability in its Action View tag helpers
Rails has a possible XSS vulnerability in its Action View tag helpers
### Impact
When a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected.
### Releases
The fixed releases are available at the normal locations.
OSV
CVE-2026-33168: Action View provides conventions and helpers for building web pages with the Rails framework
osv·2026-03-23·CVSS 2.3
CVE-2026-33168 [LOW] CVE-2026-33168: Action View provides conventions and helpers for building web pages with the Rails framework
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
OSV
Rails has a possible XSS vulnerability in its Action View tag helpers
osv·2026-03-23
CVE-2026-33168 [LOW] Rails has a possible XSS vulnerability in its Action View tag helpers
Rails has a possible XSS vulnerability in its Action View tag helpers
### Impact
When a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected.
### Releases
The fixed releases are available at the normal locations.
Red Hat
actionview: Action View: Cross-Site Scripting (XSS) via blank HTML attribute names
vendor_redhat·2026-03-23·CVSS 2.3
CVE-2026-33168 [LOW] CWE-79 actionview: Action View: Cross-Site Scripting (XSS) via blank HTML attribute names
actionview: Action View: Cross-Site Scripting (XSS) via blank HTML attribute names
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
A flaw was found in Action View, a component of the Rails framework. When a blank string is used as an HTML attribute name in Action View tag helpers, it bypas
Debian
CVE-2026-33168: rails - Action View provides conventions and helpers for building web pages with the Rai...
vendor_debian·2026·CVSS 2.3
CVE-2026-33168 [LOW] CVE-2026-33168: rails - Action View provides conventions and helpers for building web pages with the Rai...
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
https://github.com/rails/rails/commit/0b6f8002b52b9c606fd6be9e7915d9f944cf539chttps://github.com/rails/rails/commit/63f5ad83edaa0b976f82d46988d745426aa4a42dhttps://github.com/rails/rails/commit/c79a07df1e88738df8f68cb0ee759ad6128ca924https://github.com/rails/rails/releases/tag/v7.2.3.1https://github.com/rails/rails/releases/tag/v8.0.4.1https://github.com/rails/rails/releases/tag/v8.1.2.1https://github.com/rails/rails/security/advisories/GHSA-v55j-83pf-r9cq
2026-03-23
Published