logo

Technical Advisory: Ruby on Rails – Possible XSS Vulnerability in ActionView tag helpers (CVE-2022-27777)

ID: b31b7f13-db1d-5e77-a51a-b526af225bdf

STIX ID: report--b31b7f13-db1d-5e77-a51a-b526af225bdf

Feed Name: NCC Research

Threat Score
55/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

...
...

This advisory (CVE-2022-27777) describes multiple reflected and potential stored XSS vulnerabilities in Ruby on Rails tag and form helpers that allow attacker-controlled attribute names or tag names to inject arbitrary JavaScript; affected Rails versions are prior to 7.0.2.4, 6.1.5.1, 6.0.4.8, and 5.2.7.1, and fixes/patches and upgraded releases are provided by the vendor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.