CVE-2026-33168: Rails Actionview

Low severity, CVSS 2.3. EPSS: 0.7% chance of exploitation in the next 30 days.

Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, when a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Affected products

  • Rails Actionview: from 8.1.0.beta1, before 8.1.2.1 (fixed in 8.1.2.1); from 8.0.0.beta1, before 8.0.4.1 (fixed in 8.0.4.1); before 7.2.3.1 (fixed in 7.2.3.1)

Published 2026-03-23. Last modified 2026-06-17.