CVE-2026-33168: Rails Actionview
Low severity, CVSS 2.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Affected products
- Rails Actionview: from 8.1.0.beta1, before 8.1.2.1 (fixed in 8.1.2.1); from 8.0.0.beta1, before 8.0.4.1 (fixed in 8.0.4.1); before 7.2.3.1 (fixed in 7.2.3.1)
Published 2026-03-23. Last modified 2026-06-17.