← Vulnerability feed

Vulnerability record · CVE-2020-8264 · published 6 January 2021

CVE-2020-8264: Rails Actionable Exceptions middleware XSS in development mode

Rubyonrails · Rails

The actionpack gem (>= 6.0.0) contains a reflected XSS flaw in the Actionable Exceptions middleware when an application runs in development mode. A crafted URL can cause JavaScript to execute in the context of the local application, and the flaw is reachable by embedding that URL in another page. It matters mainly for development instances, where a developer browsing a malicious link could have script run against the local app.

6.1 CVSS 3.1 Medium EPSS 67% · top 0.7% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS 6.1 and high EPSS, but exploitation requires development mode plus user interaction, limiting real-world exposure.

What it is

The actionpack gem (>= 6.0.0) contains a reflected XSS flaw in the Actionable Exceptions middleware when an application runs in development mode. A crafted URL can cause JavaScript to execute in the context of the local application, and the flaw is reachable by embedding that URL in another page. It matters mainly for development instances, where a developer browsing a malicious link could have script run against the local app.

Impact

An attacker can execute JavaScript in the context of the local Rails application, potentially reading data or acting as the developer within that origin. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via a specially crafted URL handled by the Actionable Exceptions middleware; no authentication is required (PR:N) but user interaction is needed (UI:R) because the victim must open or load the crafted URL.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.66986, 99.3rd percentile) and references include an Exploit-tagged HackerOne report, indicating public exploit detail exists.

What to do

  • Upgrade the actionpack gem to a patched release per the Rails security advisory.
  • Do not run development mode on network-accessible or shared hosts; bind to localhost only.
  • Treat development-mode URLs from untrusted sources as hostile; avoid opening them directly.
  • If patching is delayed, disable or restrict the Actionable Exceptions middleware in development environments.

Detection

  • Review Rails development server logs for requests to Actionable Exceptions middleware paths with unusual query parameters.
  • Monitor for script payloads or encoded JavaScript in URLs hitting development instances.
  • Alert on development-mode servers exposed beyond localhost or reachable from untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8264 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2019-5418Ruby on Rails Action View file content disclosure via crafted Accept headersAction View in Ruby on Rails fails to properly handle specially crafted Accept headers, allowing arbitrary files on the target filesystem to be read.…KEVEPSS 99%analysed7.5CVE-2016-0752Ruby on Rails Action View render method directory traversalAction View in Ruby on Rails fails to properly sanitize pathnames passed to the render method, allowing directory traversal via '..' sequences. An ap…KEVEPSS 96%analysed7.5CVE-2014-0130Ruby on Rails implicit-render directory traversal allows arbitrary file readRuby on Rails versions before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1 contain a directory traversal flaw in the implicit-render implementa…KEVEPSS 54%analysed10.0CVE-2013-0277Rubyonrails rails vulnerabilityActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via c…EPSS 7.5%9.8CVE-2024-28103Rubyonrails rails improper input validation vulnerabilityAction Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served o…EPSS 0.66%9.8CVE-2020-8165Ruby on Rails cache store deserialization leads to RCERuby on Rails before 5.2.4.3 and before 6.0.3.1 deserializes untrusted data in MemCacheStore and RedisCacheStore, allowing attacker-supplied objects …EPSS 46%analysed9.8CVE-2019-5420Ruby on Rails development mode secret token guess leads to RCERails versions before 5.2.2.1 and before 6.0.0.beta3 generate a predictable development mode secret token. An attacker who guesses this token can com…EPSS 90%analysed8.8CVE-2020-8163Ruby on Rails render locals code injection enables RCERails versions prior to 5.0.1 allow code injection when an attacker controls the `locals` argument passed to a `render` call, leading to remote code …EPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8264), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.