CVE-2026-33168: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2026-33168 is a Cross-Site Scripting (XSS) vulnerability in Ruby on Rails' Action View tag helpers, classified as Low severity. When a blank string is used as an HTML attribute name in Action View tag helpers, the xml_name_escape function returns an empty string, bypassing attribute escaping and producing malformed HTML susceptible to mutation XSS (mXSS) attacks. Affected versions include Rails < 7.2.3.1, >= 8.0.0.beta1 and < 8.0.4.1, and >= 8.1.0.beta1 and < 8.1.2.1. The vulnerability was disclosed on March 23, 2026, and carries a CVSS v4.0 base score of 2.3 (Low) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting). In the tag_options method within actionview/lib/action_view/helpers/tag_helper.rb, when a blank string or nil is passed as an HTML attribute key, xml_name_escape returns an empty string rather than raising an error or skipping the key. This produces malformed HTML output (e.g., <img src="/img.png" ="/onerror=alert(1)">) that certain browsers may reparse, misinterpreting the crafted attribute value as a separate attribute name — a classic mXSS vector. Exploitation requires that the application allows users to supply custom HTML attribute names, making it a conditional but realistic attack surface (GitHub Advisory, Patch Commit). The issue was originally reported via HackerOne (report #3078929) by researcher "taise" (Patch Commit).

Impact

Successful exploitation could allow an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session, leading to session hijacking, credential theft, or unauthorized actions on behalf of the user. The vulnerability is limited to applications that explicitly allow user-controlled HTML attribute names in Action View tag helpers; applications that do not expose this functionality are not affected. Given the Low CVSS score and the specific preconditions required, the blast radius is relatively contained, with no direct impact on availability or server-side confidentiality (GitHub Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-33168. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (passive) and specific application conditions — namely, that the target Rails application passes user-controlled values as HTML attribute names to Action View tag helpers.

Exploitation steps

  1. Identify a vulnerable target: Find a Rails application running a version prior to 7.2.3.1, 8.0.4.1, or 8.1.2.1 that allows users to supply custom HTML attribute names rendered via Action View tag helpers.
  2. Craft a malicious input: Supply a blank string ("") as an HTML attribute name paired with a crafted value such as /onerror=alert(document.cookie) — for example, by submitting a form or API request that populates tag helper options with { "" => "/onerror=alert(1)" }.
  3. Trigger malformed HTML generation: The server renders an HTML element like <img src="/img.png" ="/onerror=alert(1)"> because xml_name_escape on a blank key returns an empty string, bypassing escaping.
  4. Browser mXSS reparsing: A browser that reparses the malformed HTML may interpret the crafted attribute value as a standalone attribute name (e.g., onerror), triggering JavaScript execution when the element is processed.
  5. Achieve XSS objective: The injected script executes in the victim's browser session, enabling session token theft, phishing, or other client-side attacks (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Logs: Web server access logs showing requests with blank or unusual HTML attribute name parameters submitted to forms or API endpoints that render Action View tag helpers.
  • Application Output: Rendered HTML pages containing malformed attribute syntax such as <tag ="value"> or elements with empty attribute names adjacent to event handler values (e.g., onerror, onload).
  • Browser/Client Side: Unexpected JavaScript execution or alert dialogs triggered by image or element load errors on pages that render user-supplied attributes; CSP violation reports referencing inline script execution from unexpected sources.

Mitigation and workarounds

Upgrade to one of the patched Rails versions: 7.2.3.1, 8.0.4.1, or 8.1.2.1, which modify tag_options in tag_helper.rb to skip blank or nil attribute keys across all iteration paths (top-level options, data hash, and aria hash loops) (Rails Release, GitHub Advisory). As a workaround prior to patching, applications should validate and sanitize user-supplied HTML attribute names before passing them to Action View tag helpers, ensuring blank strings and nil values are rejected at the application layer. IBM has also released patches for affected downstream products including IBM Aspera Shares and IBM License Metric Tool v9 (IBM Advisory).

Community reactions

The Rails security team published the advisory on March 23, 2026, crediting HackerOne researcher "taise" for responsible disclosure (GitHub Advisory). The vulnerability was bundled with several other CVEs in the same Rails patch release (7.2.3.1 / 8.0.4.1 / 8.1.2.1), which received coverage from the official Rails blog (Rails Blog). Community reaction has been muted given the Low severity rating and the narrow exploitation conditions required.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rails

Affected

sid

rails: 2:7.2.3.1+dfsg-1

Fixed

trixie

rails

Affected

Ubuntu

Unknown

bionic (esm-apps)

rails

Unknown

devel

rails

Unknown

focal (esm-apps)

rails

Unknown

jammy

rails

Unknown

jammy (esm-apps)

rails

Unknown

noble

rails

Unknown

noble (esm-apps)

rails

Unknown

resolute

rails

Unknown

Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management