CVE-2026-25500

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory` generates an HTML directory index where each file entry is rendered as a clickable link. If a file exists on disk whose basename starts with the `javascript:` scheme (e.g. `javascript:alert(1)`), the generated index contains an anchor whose `href` is exactly `javascript:alert(1)`. Clicking the entry executes JavaScript in the browser (demonstrated with `alert(1)`). Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*

History

17 Jun 2026, 10:24

Type Values Removed Values Added
Summary
  • (es) Rack es una interfaz modular para servidores web Ruby. Antes de las versiones 2.2.22, 3.1.20 y 3.2.5, `Rack::Directory` generaba un índice de directorio HTML en el que cada entrada de archivo se representaba como un enlace en el que se podía hacer clic. Si existe un archivo en el disco cuyo nombre base comienza con el esquema `javascript:` (por ejemplo, `javascript:alert(1)`), el índice generado contiene un ancla cuyo `href` es exactamente `javascript:alert(1)`. Al hacer clic en la entrada, se ejecuta JavaScript en el navegador (demostrado con `alert(1)`). Las versiones 2.2.22, 3.1.20 y 3.2.5 corrigen el problema.

19 Feb 2026, 18:26

Type Values Removed Values Added
CPE cpe:2.3:a:rack:rack:*:*:*:*:*:ruby:*:*
First Time Rack rack
Rack
References () https://github.com/rack/rack/commit/f2f225f297b99fbee3d9f51255d41f601fc40aff - () https://github.com/rack/rack/commit/f2f225f297b99fbee3d9f51255d41f601fc40aff - Patch
References () https://github.com/rack/rack/security/advisories/GHSA-whrj-4476-wvmp - () https://github.com/rack/rack/security/advisories/GHSA-whrj-4476-wvmp - Exploit, Mitigation, Vendor Advisory

18 Feb 2026, 20:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 20:18

Updated : 2026-06-17 10:24


NVD link : CVE-2026-25500

Mitre link : CVE-2026-25500

CVE.ORG link : CVE-2026-25500


JSON object : View

Products Affected

rack

  • rack
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')