Ruby on Rails security incidents

Recent advisories touching Ruby on Rails apps — searchable, enriched with exploit probability and affected versions.

UNKNOWNnpm

Malicious code in omniauth-recharge-rails-example (npm)

Malicious code in omniauth-recharge-rails-example (npm)

2 weeks ago
UNKNOWNPyPI

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after cl

openssl_encrypt versions before 1.4.0 contain a logging bug in restore_hidden_modules() that logs module counts after clearing, always showing zero restored modules and corrupting audit trails. Additionally, a race condition exists between module hiding and import hook installation where another thread could re-import blocked modules in multi-threaded environments.

openssl-encrypt: before 1.4.0

3 weeks ago
MEDIUMunknown

(rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)

(rails-html-sanitizer is responsible for sanitizing HTML fragments in R ...)

4 weeks ago
UNKNOWNnpm

Malicious code in trailserver (npm)

Malicious code in trailserver (npm)

1 month ago
LOWPyPI

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

litellm: before 1.82.0

1 month ago
MODERATERubyGems

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations

rails-html-sanitizer: 1.0.3 → 1.7.1

1 month ago
HIGHnpm

@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails

@hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails

3 months ago
CRITICALPyPI

Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism

Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism

guardrails-ai: all versions

4 months ago
HIGHRubyGems

Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests

activestorage: 8.1.0 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Support has a possible XSS vulnerability in SafeBuffer#%

Rails Active Support has a possible XSS vulnerability in SafeBuffer#%

activesupport: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Storage has possible glob injection in its DiskService

Rails Active Storage has possible glob injection in its DiskService

activestorage: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Support has a possible DoS vulnerability in its number helpers

Rails Active Support has a possible DoS vulnerability in its number helpers

activesupport: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests

Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests

activestorage: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

Rails Active Support has a possible ReDoS vulnerability in number_to_delimited

activesupport: 8.1.0.beta1 → 8.1.2.1

5 months ago
MODERATERubyGems

Rails Active Storage has possible content type bypass via metadata in direct uploads

Rails Active Storage has possible content type bypass via metadata in direct uploads

activestorage: 8.1.0.beta1 → 8.1.2.1

5 months ago
LOWRubyGems

Rails has a possible XSS vulnerability in its Action Pack debug exceptions

Rails has a possible XSS vulnerability in its Action Pack debug exceptions

actionpack: 8.1.0 → 8.1.2.1

5 months ago
HIGHRubyGems

Rails Active Storage has possible Path Traversal in DiskService

Rails Active Storage has possible Path Traversal in DiskService

activestorage: 8.1.0.beta1 → 8.1.2.1

5 months ago
LOWRubyGems

Rails has a possible XSS vulnerability in its Action View tag helpers

Rails has a possible XSS vulnerability in its Action View tag helpers

actionview: 8.1.0.beta1 → 8.1.2.1

5 months ago
UNKNOWNRubyGems

Malicious code in rails_structured_logging (RubyGems)

Malicious code in rails_structured_logging (RubyGems)

5 months ago
CRITICALExploitedunknown

Rails Ruby on Rails Path Traversal Vulnerability

https://web.archive.org/web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-5418

1 year agoEPSS 99%
HIGHRubyGems

RailsAdmin Cross-site Scripting vulnerability in the list view

RailsAdmin Cross-site Scripting vulnerability in the list view

rails_admin: 3.0.0.beta → 3.1.3

2 years ago
MEDIUMRubyGems

Rails has possible Sensitive Session Information Leak in Active Storage

Rails has possible Sensitive Session Information Leak in Active Storage

activestorage: 5.2.0 → 6.1.7.7

2 years ago
LOWRubyGems

Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch

Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch

actionpack: 7.1.0 → 7.1.3.1

2 years ago
HIGHMaven

Grails data binding causes JVM crash and/or other denial of service

Grails data binding causes JVM crash and/or other denial of service

org.grails:grails-databinding: 6.0.0 → 6.1.0

2 years ago
HIGHRubyGems

unpoly-rails Denial of Service vulnerability

unpoly-rails Denial of Service vulnerability

unpoly-rails: before 2.7.2.2

3 years ago
CRITICALExploitedunknown

Ruby on Rails Directory Traversal Vulnerability

https://nvd.nist.gov/vuln/detail/CVE-2014-0130

4 years agoEPSS 54%
CRITICALExploitedunknown

Ruby on Rails Directory Traversal Vulnerability

https://nvd.nist.gov/vuln/detail/CVE-2016-0752

4 years agoEPSS 96%
CRITICALnpm

Command Injection in lodash

Command Injection in lodash

lodash-rails: before 4.17.21

5 years ago
HIGHnpm

Potential XSS vulnerability in jQuery

Potential XSS vulnerability in jQuery

jquery: 1.12.0 → 3.5.0

6 years ago
HIGHnpm

Potential XSS vulnerability in jQuery

Potential XSS vulnerability in jQuery

jquery-rails: before 4.4.0

6 years ago
CRITICALnpm

Prototype Pollution in handlebars

Prototype Pollution in handlebars

bootstrap-wysihtml5-rails: ≥ 0.3.3.5

6 years ago
HIGHnpm

Regular Expression Denial of Service (ReDoS) in lodash

Regular Expression Denial of Service (ReDoS) in lodash

lodash-rails: 4.7.0 → 4.17.11

7 years ago
HIGHnpm

Prototype Pollution in lodash

Prototype Pollution in lodash

lodash-rails: before 4.17.12

7 years ago
MEDIUMRubyGems

Bootstrap Vulnerable to Cross-Site Scripting

Bootstrap Vulnerable to Cross-Site Scripting

bootstrap: before 4.3.1

7 years ago

Tooling for Ruby on Rails

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.