Executive brief
Avo has a XSS vulnerability on `return_to` param
Affected products
- RubyGems avo
Junglewise Threat Intelligence
CVE-2026-33209 · Severity: medium · CVSS 4 · Published 2026-03-18
Technologies: avo (RubyGems). Vendors: RubyGems.
Avo has a XSS vulnerability on `return_to` param