RubySec

Providing security resources for the Ruby community

CVE-2025-67202 (sidekiq-cron): Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL

Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL

Published: May 07, 2026

SECURITY IDENTIFIERS

GEM

sidekiq-cron

SEVERITY

CVSS v3.x: 6.1 (Medium)

PATCHED VERSIONS

>= 2.4.0

DESCRIPTION

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

RELATED