GHSA-cr3x-7m39-c6jq
GitHub Security Advisory
Remote code execution via user-provided local names in ActionView
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that would allow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
Affected Packages
RubyGems
actionview
Affected versions:
0
(fixed in 4.2.11.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 1, 2025 6:44 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.