{"id":"CVE-2026-33209","aliases":["GHSA-762r-27w2-q22j"],"url":"https://o3.security/vulnerability/CVE-2026-33209","summary":"Avo has a XSS vulnerability on `return_to` param","details":"Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site scripting (XSS) vulnerability exists in the return_to query parameter used in the avo interface. An attacker can craft a malicious URL that injects arbitrary JavaScript, which is executed when he clicks a dynamically generated navigation button. This issue has been patched in version 3.30.3.","published":"2026-03-20T22:39:19.422Z","modified":"2026-08-12T03:51:15.326519567Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"avo","fixedVersion":"3.30.3"}],"fix":{"url":"https://github.com/avo-hq/avo/commit/4453d39ddc6309f3bc8ada73ef21e1971112de7d","label":"avo-hq/avo@4453d39"},"references":[{"type":"WEB","url":"https://github.com/avo-hq/avo/releases/tag/v3.30.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33209.json"},{"type":"ADVISORY","url":"https://github.com/avo-hq/avo/security/advisories/GHSA-762r-27w2-q22j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33209"},{"type":"FIX","url":"https://github.com/avo-hq/avo/commit/4453d39ddc6309f3bc8ada73ef21e1971112de7d"},{"type":"FIX","url":"https://github.com/avo-hq/avo/pull/4330"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.326519567Z"}}