GHSA-xv9c-mjw8-79gf

Suggest an improvement
Source
https://github.com/advisories/GHSA-xv9c-mjw8-79gf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-xv9c-mjw8-79gf/GHSA-xv9c-mjw8-79gf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xv9c-mjw8-79gf
Aliases
  • CVE-2025-67202
Published
2026-05-07T15:38:41Z
Modified
2026-05-29T22:00:14.621971136Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL
Details

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed_at": "2026-05-12T16:19:17Z",
    "github_reviewed": true,
    "severity": "MODERATE",
    "nvd_published_at": "2026-05-07T15:16:04Z"
}
References

Affected packages

RubyGems / sidekiq-cron

Package

Name
sidekiq-cron
Purl
pkg:gem/sidekiq-cron

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.0

Affected versions

0.*
0.1.0
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.7.0
1.8.0
1.9.0
1.9.1
1.10.0
1.10.1
1.11.0
1.12.0
2.*
2.0.0.rc1
2.0.0.rc2
2.0.0
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-xv9c-mjw8-79gf/GHSA-xv9c-mjw8-79gf.json"