CVE-2024-26143: Rubyonrails Rails
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
Affected products
- Rubyonrails Rails: from 7.0.0, before 7.0.8.1 (fixed in 7.0.8.1); from 7.1.0, before 7.1.3.1 (fixed in 7.1.3.1)
Published 2024-02-27. Last modified 2026-06-17.