Launch Week Day 1: Announcing Security Design Review
UNKNOWN RubyGems

Avo has a XSS vulnerability on `return_to` param

GHSA-762r-27w2-q22j · CVE-2026-33209

Published · Modified

Description

Description

A reflected cross-site scripting (XSS) vulnerability exists in the return_to query parameter used in the avo interface.

An attacker can craft a malicious URL that injects arbitrary JavaScript, which is executed when he clicks a dynamically generated navigation button.

Impact

This vulnerability may allow execution of arbitrary JavaScript in the context of the application.

Impact varies depending on deployment:

  • In unauthenticated setups: exploitable via crafted links sent to users
  • In authenticated setups: limited to authenticated users and requires interaction

Ready to move

Start Securing

Free, no credit card | First findings in minutes