Critical Vulnerabilities Found in Ruby on Rails ViewComponent Framework

Critical Vulnerabilities Found in Ruby on Rails ViewComponent Framework

First seen 19 Jul 2026, 08:42 UTC Secably 75% similarity 72.0

Article Content

Browse articles
ThreatCluster

Two vulnerabilities, CVE-2026-54497 and CVE-2026-54498, were published on July 17, 2026, affecting the Ruby on Rails ViewComponent framework versions 4.0.0 to 4.12.0. CVE-2026-54497 has a CVSS score of 6.8 and allows for resource exposure due to stale context being retained across renders, potentially leading to unauthorized UI rendering. CVE-2026-54498, with a CVSS score of 8.7, presents an XSS risk where unsafe HTML strings can bypass escaping, allowing for injection of malicious scripts. Both vulnerabilities are fixed in version 4.12.0. Users of the affected framework are urged to update immediately to mitigate risks. The EPSS indicates a significant likelihood of exploitation in the wild for both vulnerabilities.

Key Points: • CVE-2026-54497 allows unauthorized UI rendering due to stale context retention. • CVE-2026-54498 poses a serious XSS risk with a CVSS score of 8.7. • Both vulnerabilities are patched in ViewComponent version 4.12.0.

ThreatCluster AI

Timeline

2026-07-17
CVE-2026-54497 published
CVE-2026-54497 disclosed, affecting ViewComponent versions 4.0.0 to 4.12.0, allowing resource exposure.
Secably
2026-07-17
CVE-2026-54498 published
CVE-2026-54498 disclosed, affecting ViewComponent versions 4.0.0 to 4.12.0, creating an XSS risk.
Secably
2026-07-18
Security advisory issued
Advisories released urging users to update to ViewComponent version 4.12.0 to mitigate risks.
Secably

Community

Browse all →