
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33168 is a Cross-Site Scripting (XSS) vulnerability in Ruby on Rails' Action View tag helpers, classified as Low severity. When a blank string is used as an HTML attribute name in Action View tag helpers, the xml_name_escape function returns an empty string, bypassing attribute escaping and producing malformed HTML susceptible to mutation XSS (mXSS) attacks. Affected versions include Rails < 7.2.3.1, >= 8.0.0.beta1 and < 8.0.4.1, and >= 8.1.0.beta1 and < 8.1.2.1. The vulnerability was disclosed on March 23, 2026, and carries a CVSS v4.0 base score of 2.3 (Low) (GitHub Advisory, Feedly).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation / Cross-Site Scripting). In the tag_options method within actionview/lib/action_view/helpers/tag_helper.rb, when a blank string or nil is passed as an HTML attribute key, xml_name_escape returns an empty string rather than raising an error or skipping the key. This produces malformed HTML output (e.g., <img src="/img.png" ="/onerror=alert(1)">) that certain browsers may reparse, misinterpreting the crafted attribute value as a separate attribute name — a classic mXSS vector. Exploitation requires that the application allows users to supply custom HTML attribute names, making it a conditional but realistic attack surface (GitHub Advisory, Patch Commit). The issue was originally reported via HackerOne (report #3078929) by researcher "taise" (Patch Commit).
Successful exploitation could allow an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session, leading to session hijacking, credential theft, or unauthorized actions on behalf of the user. The vulnerability is limited to applications that explicitly allow user-controlled HTML attribute names in Action View tag helpers; applications that do not expose this functionality are not affected. Given the Low CVSS score and the specific preconditions required, the blast radius is relatively contained, with no direct impact on availability or server-side confidentiality (GitHub Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-33168. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (passive) and specific application conditions — namely, that the target Rails application passes user-controlled values as HTML attribute names to Action View tag helpers.
"") as an HTML attribute name paired with a crafted value such as /onerror=alert(document.cookie) — for example, by submitting a form or API request that populates tag helper options with { "" => "/onerror=alert(1)" }.<img src="/img.png" ="/onerror=alert(1)"> because xml_name_escape on a blank key returns an empty string, bypassing escaping.onerror), triggering JavaScript execution when the element is processed.<tag ="value"> or elements with empty attribute names adjacent to event handler values (e.g., onerror, onload).Upgrade to one of the patched Rails versions: 7.2.3.1, 8.0.4.1, or 8.1.2.1, which modify tag_options in tag_helper.rb to skip blank or nil attribute keys across all iteration paths (top-level options, data hash, and aria hash loops) (Rails Release, GitHub Advisory). As a workaround prior to patching, applications should validate and sanitize user-supplied HTML attribute names before passing them to Action View tag helpers, ensuring blank strings and nil values are rejected at the application layer. IBM has also released patches for affected downstream products including IBM Aspera Shares and IBM License Metric Tool v9 (IBM Advisory).
The Rails security team published the advisory on March 23, 2026, crediting HackerOne researcher "taise" for responsible disclosure (GitHub Advisory). The vulnerability was bundled with several other CVEs in the same Rails patch release (7.2.3.1 / 8.0.4.1 / 8.1.2.1), which received coverage from the official Rails blog (Rails Blog). Community reaction has been muted given the Low severity rating and the narrow exploitation conditions required.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."