Skip to content
Critical Vulnerabilities Found in Ruby on Rails ViewComponent Framework

Critical Vulnerabilities Found in Ruby on Rails ViewComponent Framework

First seen 19 Jul 2026, 08:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 20, 2026 at 08:04 UTC

Two vulnerabilities, CVE-2026-54497 and CVE-2026-54498, were published on July 17, 2026, affecting the Ruby on Rails ViewComponent framework versions 4.0.0 to 4.12.0. CVE-2026-54497 has a CVSS score of 6.8 and allows for resource exposure due to stale context being retained across renders, potentially leading to unauthorized UI rendering. CVE-2026-54498, with a CVSS score of 8.7, presents an XSS risk where unsafe HTML strings can bypass escaping, allowing for injection of malicious scripts. Both vulnerabilities are fixed in version 4.12.0. Users of the affected framework are urged to update immediately to mitigate risks. The EPSS indicates a significant likelihood of exploitation in the wild for both vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 54d ago How this analysis works

Timeline

2026-07-17
CVE-2026-54497 published
CVE-2026-54497 disclosed, affecting ViewComponent versions 4.0.0 to 4.12.0, allowing resource exposure.
Secably
2026-07-17
CVE-2026-54498 published
CVE-2026-54498 disclosed, affecting ViewComponent versions 4.0.0 to 4.12.0, creating an XSS risk.
Secably
2026-07-18
Security advisory issued
Advisories released urging users to update to ViewComponent version 4.12.0 to mitigate risks.
Secably

More articles in this cluster (2)

Following this threat?

Track CVE-2026-54497 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed