Vulnerability record · CVE-2020-8264 · published 6 January 2021
CVE-2020-8264: Rails Actionable Exceptions middleware XSS in development mode
Rubyonrails · Rails
The actionpack gem (>= 6.0.0) contains a reflected XSS flaw in the Actionable Exceptions middleware when an application runs in development mode. A crafted URL can cause JavaScript to execute in the context of the local application, and the flaw is reachable by embedding that URL in another page. It matters mainly for development instances, where a developer browsing a malicious link could have script run against the local app.
Description
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS 6.1 and high EPSS, but exploitation requires development mode plus user interaction, limiting real-world exposure.
What it is
The actionpack gem (>= 6.0.0) contains a reflected XSS flaw in the Actionable Exceptions middleware when an application runs in development mode. A crafted URL can cause JavaScript to execute in the context of the local application, and the flaw is reachable by embedding that URL in another page. It matters mainly for development instances, where a developer browsing a malicious link could have script run against the local app.
Impact
An attacker can execute JavaScript in the context of the local Rails application, potentially reading data or acting as the developer within that origin. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network via a specially crafted URL handled by the Actionable Exceptions middleware; no authentication is required (PR:N) but user interaction is needed (UI:R) because the victim must open or load the crafted URL.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.66986, 99.3rd percentile) and references include an Exploit-tagged HackerOne report, indicating public exploit detail exists.
What to do
- Upgrade the actionpack gem to a patched release per the Rails security advisory.
- Do not run development mode on network-accessible or shared hosts; bind to localhost only.
- Treat development-mode URLs from untrusted sources as hostile; avoid opening them directly.
- If patching is delayed, disable or restrict the Actionable Exceptions middleware in development environments.
Detection
- Review Rails development server logs for requests to Actionable Exceptions middleware paths with unusual query parameters.
- Monitor for script payloads or encoded JavaScript in URLs hitting development instances.
- Alert on development-mode servers exposed beyond localhost or reachable from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://groups.google.com/g/rubyonrails-security/c/yQzUVfv42jk/m/oJWw-xhNAQAJ | Mailing ListThird Party Advisory |
| https://hackerone.com/reports/904059 | ExploitPatchThird Party Advisory |
| https://groups.google.com/g/rubyonrails-security/c/yQzUVfv42jk/m/oJWw-xhNAQAJ | Mailing ListThird Party Advisory |
| https://hackerone.com/reports/904059 | ExploitPatchThird Party Advisory |
Track CVE-2020-8264 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8264), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.