Junglewise Threat Intelligence

CVE-2026-33167: Rails has a possible XSS vulnerability in its Action Pack debug exceptions

CVE-2026-33167 · Severity: medium · CVSS 4 · Published 2026-03-23

Technologies: actionpack (RubyGems). Vendors: RubyGems.

Executive brief

### Impact The debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development.

### Releases The fixed releases are available at the normal locations.

### Credit This issue was responsibly reported by Hackerone researcher [fbettag](https://hackerone.com/fbettag).

Affected products

  • RubyGems actionpack

References

Related threats