Impact
When a blank string is used as an HTML attribute name in Action View tag helpers, the attribute escaping is bypassed, producing malformed HTML. A carefully crafted attribute value could then be misinterpreted by the browser as a separate attribute name, possibly leading to XSS. Applications that allow users to specify custom HTML attributes are affected.
Releases
The fixed releases are available at the normal locations.
- CVE-2026-33168
- GHSA-v55j-83pf-r9cq
Versions affected
- actionview >= 8.1, < 8.1.2.1 (patched in 8.1.2.1)
- actionview >= 8.0, < 8.0.4.1 (patched in 8.0.4.1)
- actionview < 7.2.3.1 (patched in 7.2.3.1)