[CVE-2026-33168] Possible XSS vulnerability in Action View tag helpers

Impact

When a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected.

Releases

The fixed releases are available at the normal locations.

  • CVE-2026-33168
  • GHSA-v55j-83pf-r9cq

Versions affected

  • actionview >= 8.1, < 8.1.2.1 (patched in 8.1.2.1)
  • actionview >= 8.0, < 8.0.4.1 (patched in 8.0.4.1)
  • actionview < 7.2.3.1 (patched in 7.2.3.1)

Patches

1 Like