Ruby on Rails security incidents
Recent advisories touching Ruby on Rails apps — searchable, enriched with exploit probability and affected versions.
Malicious code in omniauth-recharge-rails-example (npm)
Malicious code in omniauth-recharge-rails-example (npm)
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after cl
openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.
openssl-encrypt: before 1.4.0
(rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)
(rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)
Malicious code in trailserver (npm)
Malicious code in trailserver (npm)
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
litellm: before 1.82.0
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
rails-html-sanitizer: 1.0.3 → 1.7.1
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
guardrails-ai: all versions
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
activestorage: 8.1.0 → 8.1.2.1
Rails Active Support has a possible XSS vulnerability in SafeBuffer#%
Rails Active Support has a possible XSS vulnerability in SafeBuffer#%
activesupport: 8.1.0.beta1 → 8.1.2.1
Rails Active Storage has possible glob injection in its DiskService
Rails Active Storage has possible glob injection in its DiskService
activestorage: 8.1.0.beta1 → 8.1.2.1
Rails Active Support has a possible DoS vulnerability in its number helpers
Rails Active Support has a possible DoS vulnerability in its number helpers
activesupport: 8.1.0.beta1 → 8.1.2.1
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
activestorage: 8.1.0.beta1 → 8.1.2.1
Rails Active Support has a possible ReDoS vulnerability in number_to_delimited
Rails Active Support has a possible ReDoS vulnerability in number_to_delimited
activesupport: 8.1.0.beta1 → 8.1.2.1
Rails Active Storage has possible content type bypass via metadata in direct uploads
Rails Active Storage has possible content type bypass via metadata in direct uploads
activestorage: 8.1.0.beta1 → 8.1.2.1
Rails has a possible XSS vulnerability in its Action Pack debug exceptions
Rails has a possible XSS vulnerability in its Action Pack debug exceptions
actionpack: 8.1.0 → 8.1.2.1
Rails Active Storage has possible Path Traversal in DiskService
Rails Active Storage has possible Path Traversal in DiskService
activestorage: 8.1.0.beta1 → 8.1.2.1
Rails has a possible XSS vulnerability in its Action View tag helpers
Rails has a possible XSS vulnerability in its Action View tag helpers
actionview: 8.1.0.beta1 → 8.1.2.1
Malicious code in rails_structured_logging (RubyGems)
Malicious code in rails_structured_logging (RubyGems)
Rails Ruby on Rails Path Traversal Vulnerability
https://web.archive.org/web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-5418
RailsAdmin Cross-site Scripting vulnerability in the list view
RailsAdmin Cross-site Scripting vulnerability in the list view
rails_admin: 3.0.0.beta → 3.1.3
Rails has possible Sensitive Session Information Leak in Active Storage
Rails has possible Sensitive Session Information Leak in Active Storage
activestorage: 5.2.0 → 6.1.7.7
Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch
Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch
actionpack: 7.1.0 → 7.1.3.1
Grails data binding causes JVM crash and/or other denial of service
Grails data binding causes JVM crash and/or other denial of service
org.grails:grails-databinding: 6.0.0 → 6.1.0
unpoly-rails Denial of Service vulnerability
unpoly-rails Denial of Service vulnerability
unpoly-rails: before 2.7.2.2
Ruby on Rails Directory Traversal Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2014-0130
Ruby on Rails Directory Traversal Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2016-0752
Command Injection in lodash
Command Injection in lodash
lodash-rails: before 4.17.21
Potential XSS vulnerability in jQuery
Potential XSS vulnerability in jQuery
jquery: 1.12.0 → 3.5.0
Potential XSS vulnerability in jQuery
Potential XSS vulnerability in jQuery
jquery-rails: before 4.4.0
Prototype Pollution in handlebars
Prototype Pollution in handlebars
bootstrap-wysihtml5-rails: ≥ 0.3.3.5
Regular Expression Denial of Service (ReDoS) in lodash
Regular Expression Denial of Service (ReDoS) in lodash
lodash-rails: 4.7.0 → 4.17.11
Prototype Pollution in lodash
Prototype Pollution in lodash
lodash-rails: before 4.17.12
Bootstrap Vulnerable to Cross-Site Scripting
Bootstrap Vulnerable to Cross-Site Scripting
bootstrap: before 4.3.1
Tooling for Ruby on Rails
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.