RubySec

Providing security resources for the Ruby community

CVE-2026-33209 (avo): Avo has a XSS vulnerability on `return_to` param

ADVISORIES

GEM

avo

PATCHED VERSIONS

  • >= 3.30.3

DESCRIPTION

Description

A reflected cross-site scripting (XSS) vulnerability exists in the return_to query parameter used in the avo interface.

An attacker can craft a malicious URL that injects arbitrary JavaScript, which is executed when he clicks a dynamically generated navigation button.

Impact

This vulnerability may allow execution of arbitrary JavaScript in the context of the application.

Impact varies depending on deployment:

  • In unauthenticated setups: exploitable via crafted links sent to users.
  • In authenticated setups: limited to authenticated users and requires interaction.

RELATED