Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2026-05-12T16:19:17Z",
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2026-05-07T15:16:04Z"
}