CVE-2026-33167 | rails actionpack up to 8.1/8.1.2.1 consider_all_requests_local cross site scripting (GHSA-pgm4-439c-5jp6)
A vulnerability, which was classified as problematic, was found in rails actionpack up to 8.1/8.1.2.1. Affected is the function consider_all_requests_local. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-33167. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.