File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ ---
2+ layout : advisory
3+ title : ' CVE-2025-67202 (sidekiq-cron): Sidekiq-cron is vulnerable to a cross-site
4+ scripting (xss) vulnerability via crafted URL'
5+ comments : false
6+ categories :
7+ - sidekiq-cron
8+ advisory :
9+ gem : sidekiq-cron
10+ cve : 2025-67202
11+ ghsa : xv9c-mjw8-79gf
12+ url : https://github.com/advisories/GHSA-xv9c-mjw8-79gf
13+ title : Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability
14+ via crafted URL
15+ date : 2026-05-07
16+ description : |-
17+ Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq,
18+ is vulnerable to a cross-site scripting (xss) vulnerability via crafted
19+ URL being rended from cron.erb.
20+ cvss_v3 : 6.1
21+ patched_versions :
22+ - " >= 2.4.0"
23+ related :
24+ url :
25+ - https://nvd.nist.gov/vuln/detail/CVE-2025-67202
26+ - https://github.com/sidekiq-cron/sidekiq-cron/releases/tag/v2.4.0
27+ - https://github.com/sidekiq-cron/sidekiq-cron/pull/568
28+ - https://github.com/sidekiq-cron/sidekiq-cron/commit/7b4ae4822f93ef4646f5cb55500ca4e25662db7c
29+ - https://github.com/sidekiq-cron/sidekiq-cron/issues/569
30+ - https://github.com/advisories/GHSA-xv9c-mjw8-79gf
31+ ---
You can’t perform that action at this time.
0 commit comments