CVE-2026-33167Disclosure(rubyonrails / rails)

LOWCVSS 6.1 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rails

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-03-24)
  • 5 total mentions across 2 days

Affected systems

Products
rails

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-23: 1Mentions · 2026-03-24: 4Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 303-2303-24
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-231
Disclosure1
2026-03-244
Disclosure3General1
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33167 Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not prop… https://www.cve.org/CVERecord?id=CVE-2026-33167 ----- Traducción: CVE-2026-33167 Act… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑33167 relating to Rails Action Pack’s debug exception handling and links to the official CVE record, but offers no proof of exploitation, patch, or workaround details.

    0000031
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33167 Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not prop… https://www.cve.org/CVERecord?id=CVE-2026-33167

    Post summary

    The passage references CVE‑2026‑33167 as a vulnerability in Rails Action Pack for versions prior to 8.1.2.1, but it offers only the affected versions and no proof‑of‑concept, exploit, or remedial information.

    00000172
    56.8K followersView on X
  • TRONCAL Yannick@ytroncal
    Disclosure

    CVE-2026-33167: CVE-2026-33167: Cross-Site Scripting (XSS) in Ruby on Rails Action Pack Debug Exceptions https://dev.to/cverports/cve-2026-33167-cve-2026-33167-cross-site-scripting-xss-in-ruby-on-rails-action-pack-debug-4op6

    Post summary

    The text announces CVE‑2026‑33167, a XSS issue in Ruby on Rails Action Pack Debug Exceptions, with a link to an article that details the vulnerability.

    0000035
    140 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33167 Cross-Site Scripting in Ruby on Rails Action Pack 8.1 Before 8.1.2.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33167

    Post summary

    A Cross‑Site Scripting vulnerability is reported in Ruby on Rails Action Pack 8.1 versions before 8.1.2.1, as documented by a vulnerability database entry, but no additional details on PoCs, exploits, patches, or active exploitation are provided.

    0000046
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33167 - Rails has a possible XSS vulnerability in its Action Pack debug exceptions Intel Report: https://ift.tt/UQExrgt

    Post summary

    The alert announces a newly identified possible XSS vulnerability in Rails Action Pack debug exceptions (CVE‑2026‑33167), providing basic technical details but no PoC, exploit code, or patch information.

    0000042
    289 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprubyonrailsrails---

Explore more