RubySec

Providing security resources for the Ruby community

CVE-2024-41673 (decidim): Decidim has a cross-site scripting vulnerability in the version control page

ADVISORIES

GEM

decidim

SEVERITY

CVSS v3.x: 7.1 (High)

PATCHED VERSIONS

  • >= 0.27.8

DESCRIPTION

Impact

The version control feature used in resources is subject to potential cross-site scripting (XSS) attack through a malformed URL.

Workarounds

Not available

References

OWASP ASVS v4.0.3-5.1.3

Credits

This issue was discovered in a security audit organized by Open Source Politics against Decidim done during July 2025.

RELATED