Executive brief
A vulnerability in the Ruby on Rails Active Support library could allow attackers to perform Cross-Site Scripting (XSS) attacks. Active Support provides essential utility functions for the Rails web framework, including tools for safely handling web content. An exploit could allow an attacker to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions or data theft.
Technical details
A vulnerability exists in Active Support's SafeBuffer#% method where it fails to correctly propagate the @html_unsafe flag to newly created buffers. If a SafeBuffer is mutated in place (using methods like gsub!) and subsequently formatted using the % operator with untrusted arguments, the resulting object incorrectly identifies as html_safe. This flaw allows an attacker to bypass ERB auto-escaping mechanisms, leading to reflected or stored XSS. The issue is resolved in versions 8.1.2.1, 8.0.4.1, and 7.2.3.1.
Affected products
- Ruby on Rails activesupport >= 8.1.0.beta1, < 8.1.2.1
- Ruby on Rails activesupport >= 8.0.0.beta1, < 8.0.4.1
- Ruby on Rails activesupport < 7.2.3.1
Timeline
- 2026-03-23: disclosed
- 2026-03-23: advisory
- 2026-03-23: patched