{"id":"CVE-2024-26143","aliases":["BIT-rails-2024-26143","GHSA-9822-6m93-xqf4"],"url":"https://o3.security/vulnerability/CVE-2024-26143","summary":"Rails Possible XSS Vulnerability in Action Controller","details":"# Possible XSS Vulnerability in Action Controller\n\nThere is a possible XSS vulnerability when using the translation helpers\n(`translate`, `t`, etc) in Action Controller. This vulnerability has been\nassigned the CVE identifier CVE-2024-26143.\n\nVersions Affected:  >= 7.0.0.\nNot affected:       < 7.0.0\nFixed Versions:     7.1.3.1, 7.0.8.1\n\nImpact\n------\nApplications using translation methods like `translate`, or `t` on a\ncontroller, with a key ending in \"_html\", a `:default` key which contains\nuntrusted user input, and the resulting string is used in a view, may be\nsusceptible to an XSS vulnerability.\n\nFor example, impacted code will look something like this:\n\n```ruby\nclass ArticlesController < ApplicationController\n  def show  \n    @message = t(\"message_html\", default: untrusted_input)\n    # The `show` template displays the contents of `@message`\n  end\nend\n```\n\nTo reiterate the pre-conditions, applications must:\n\n* Use a translation function from a controller (i.e. _not_ I18n.t, or `t` from\n  a view)\n* Use a key that ends in `_html`\n* Use a default value where the default value is untrusted and unescaped input\n* Send the text to the victim (whether that's part of a template, or a\n  `render` call)\n\nAll users running an affected release should either upgrade or use one of the\nworkarounds immediately.\n\nReleases\n--------\nThe fixed releases are available at the normal locations.\n\nWorkarounds\n-----------\nThere are no feasible workarounds for this issue.\n\nPatches\n-------\nTo aid users who aren't able to upgrade immediately we have provided patches for\nthe two supported release series. They are in git-am format and consist of a\nsingle changeset.\n\n*  7-0-translate-xss.patch - Patch for 7.0 series\n*  7-1-translate-xss.patch - Patch for 7.1 series\n\nCredits\n-------\n\nThanks to [ooooooo_q](https://hackerone.com/ooooooo_q) for the patch and fix!","published":"2024-02-27T15:33:54.643Z","modified":"2026-09-09T03:45:11.817763095Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"actionpack","fixedVersion":"7.0.8.1"},{"ecosystem":"RubyGems","name":"actionpack","fixedVersion":"7.1.3.1"},{"ecosystem":"RubyGems","name":"rails","fixedVersion":"7.0.8.1"},{"ecosystem":"RubyGems","name":"rails","fixedVersion":"7.1.3.1"}],"fix":{"url":"https://github.com/rails/rails/commit/4c83b331092a79d58e4adffe4be5f250fa5782cc","label":"rails/rails@4c83b33"},"references":[{"type":"WEB","url":"https://discuss.rubyonrails.org/t/possible-xss-vulnerability-in-action-controller/84947"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26143.json"},{"type":"ADVISORY","url":"https://github.com/rails/rails/security/advisories/GHSA-9822-6m93-xqf4"},{"type":"ADVISORY","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2024-26143.yml"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26143"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240510-0004/"},{"type":"FIX","url":"https://github.com/rails/rails/commit/4c83b331092a79d58e4adffe4be5f250fa5782cc"},{"type":"FIX","url":"https://github.com/rails/rails/commit/5187a9ef51980ad1b8e81945ebe0462d28f84f9e"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240510-0004"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T03:45:11.817763095Z"}}