{"id":"CVE-2024-21636","aliases":["GHSA-wf2x-8w6j-qw37"],"url":"https://o3.security/vulnerability/CVE-2024-21636","summary":"view_component Cross-site Scripting vulnerability","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nThis is an XSS vulnerability that has the potential to impact anyone rendering a component directly from a controller with the view_component gem. Note that only components that define a [`#call` method](https://viewcomponent.org/guide/templates.html#call) (i.e. instead of using a sidecar template) are affected. The return value of the `#call` method is not sanitized and can include user-defined content.\n\nIn addition, the return value of the [`#output_postamble` method](https://viewcomponent.org/api.html#output_postamble--string) is not sanitized, which can also lead to XSS issues.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nVersions 3.9.0 has been released and fully mitigates both the `#call` and the `#output_postamble` vulnerabilities.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nSanitize the return value of `#call`, eg:\n\n```ruby\nclass MyComponent < ApplicationComponent\n  def call\n    html_escape(\"<div>#{user_input}</div>\")\n  end\nend\n```\n\n### References\n_Are there any links users can visit to find out more?_\n\nhttps://github.com/ViewComponent/view_component/pull/1950\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\nOpen an issue in the [github/view_component](https://github.com/github/view_component) project.","published":"2024-01-04T20:09:08.564Z","modified":"2026-08-12T03:51:36.245758597Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00495,"percentile":0.40483,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"view_component","fixedVersion":"3.9.0"},{"ecosystem":"RubyGems","name":"view_component","fixedVersion":"2.83.0"}],"fix":{"url":"https://github.com/ViewComponent/view_component/commit/0d26944a8d2730ea40e60eae23d70684483e5017","label":"ViewComponent/view_component@0d26944"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21636.json"},{"type":"ADVISORY","url":"https://github.com/ViewComponent/view_component/security/advisories/GHSA-wf2x-8w6j-qw37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21636"},{"type":"FIX","url":"https://github.com/ViewComponent/view_component/commit/0d26944a8d2730ea40e60eae23d70684483e5017"},{"type":"FIX","url":"https://github.com/ViewComponent/view_component/commit/c43d8bafa7117cbce479669a423ab266de150697"},{"type":"FIX","url":"https://github.com/ViewComponent/view_component/pull/1950"},{"type":"FIX","url":"https://github.com/ViewComponent/view_component/pull/1962"},{"type":"PACKAGE","url":"https://github.com/ViewComponent/view_component"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/view_component/CVE-2024-21636.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.245758597Z"}}