activeadmin
The administration framework for Ruby on Rails.
Activity
- Latest release
- 2mo ago
- Total releases
- 100
- Cadence
- ~17 days
- Last 12 months
- 10
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Sep 07, 2010
| Version | Released | |
|---|---|---|
3.5.2
patch
|
3.5.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.5.1
patch
|
3.5.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
3.5.0
minor
|
3.5.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.0.0.beta22
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta22
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta21
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta21
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta20
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta20
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta19
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta19
pre
Dependencies (8)
Changelog
Compare changes
|
|
3.4.0
minor
|
3.4.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.0.0.beta18
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta18
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta17
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta17
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta16
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta16
pre
Dependencies (8)
Changelog
Compare changes
|
|
3.3.0
minor
|
3.3.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.0.0.beta15
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta15
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta14
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta14
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta13
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta13
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta12
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta12
pre
Dependencies (8)
Changelog
Compare changes
|
|
3.2.5
patch
|
3.2.5
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.0.0.beta11
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta11
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta10
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta10
pre
Dependencies (8)
Changelog
Compare changes
|
|
3.2.4
patch
|
3.2.4
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.0.0.beta9
pre
|
4.0.0.beta9
pre
Dependencies (8)
Changelog
Compare changes
|
|
3.2.3
patch
|
3.2.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.0.0.beta8
pre
|
4.0.0.beta8
pre
Dependencies (8)
Changelog
Compare changes
|
|
4.0.0.beta7
pre
|
4.0.0.beta7
pre
Dependencies (8)
Changelog
Compare changes
|
|
3.2.2
patch
|
3.2.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.0.0.beta6
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta6
pre
Dependencies (8)
Changelog
Compare changes
|
|
3.2.1
patch
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.2.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
4.0.0.beta5
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta5
pre
Dependencies (7)
Changelog
Compare changes
|
|
4.0.0.beta4
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta4
pre
Dependencies (7)
Changelog
Compare changes
|
|
4.0.0.beta2
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta2
pre
Dependencies (7)
Changelog
Compare changes
|
|
4.0.0.beta3
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta3
pre
Dependencies (7)
Changelog
Compare changes
|
|
4.0.0.beta1
pre
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
4.0.0.beta1
pre
Dependencies (7)
Changelog
Compare changes
|
|
3.2.0
minor
1 CVE
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
3.1.0
minor
2 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.1.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
3.0.0
major
2 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.0
major
Dependencies (8)
Changelog
Compare changes
|
|
2.14.0
minor
2 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.14.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.13.1
patch
2 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.13.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.13.0
minor
2 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.13.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.12.0
minor
2 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.12.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.11.2
patch
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.11.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.11.1
patch
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.11.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.11.0
minor
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.11.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.10.1
patch
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.10.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.10.0
minor
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.10.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.9.0
minor
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.9.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.8.1
patch
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.8.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.8.0
minor
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.8.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.7.0
minor
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.7.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.6.1
patch
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.6.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.6.0
minor
3 CVEs
CVE-2024-37031
GHSA-9mg6-x45v-hcfm
Jun 02, 2024
activeadmin vulnerable to stored persistent cross-site scripting (XSS) in dynamic form legends
7.2
/ 10
High
Network
Low
None
None
Changed
Low
Low
None
ImpactUsers settings their active admin form legends dynamically may be vulnerable to stored XSS, as long as its value can be injected directly by a malicious user. For example:
Then a malicious user could create an entity with a payload that would get executed in the active admin administrator's browser. Both PatchesThe problem has been fixed in ActiveAdmin 3.2.2 and ActiveAdmin 4.0.0.beta7. WorkaroundsUsers can workaround this problem without upgrading by explicitly escaping the form name using an HTML escaping utility. For example:
Upgrading is of course recommended though. Referenceshttps://owasp.org/www-community/attacks/xss/#stored-xss-attacks Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 63 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
3.2.0
3.2.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
Fixed in
3.2.2
4.0.0.beta7
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-51763
GHSA-xhvv-3jww-c487
Dec 28, 2023
ActiveAdmin CSV Injection leading to sensitive information disclosure
5.2
/ 10
Medium
Local
Low
High
Required
Changed
Low
Low
Low
ImpactIn ActiveAdmin versions prior to 3.2.0, maliciously crafted spreadsheet formulas could be uploaded as part of admin data that, when exported to a CSV file and the imported to a spreadsheet program like libreoffice, could lead to remote code execution and private data exfiltration. The attacker would need privileges to upload data to the same ActiveAdmin application as the victim, and would need the victim to possibly ignore security warnings from their spreadsheet program. PatchesVersions 3.2.0 and above fixed the problem by escaping any data starting with WorkaroundsOnly turn on formula evaluation in spreadsheet programs when importing CSV after explicitly reviewing the file. Referenceshttps://owasp.org/www-community/attacks/CSV_Injection https://github.com/activeadmin/activeadmin/pull/8167 Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 55 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.12.0
2.13.0
2.13.1
2.14.0
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
3.0.0
3.1.0
Fixed in
3.2.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-50448
GHSA-356j-hg45-x525
Dec 15, 2023
Potential CSV export data leak
8.4
/ 10
High
Network
Low
High
Required
Changed
High
High
High
ImpactIn ActiveAdmin versions prior to 2.12.0, a concurrency issue was found that could allow a malicious actor to be able to access potentially private data that belongs to another user. The bug affects the functionality to export data as CSV files, and was caused by a variable holding the collection to be exported being shared across threads and not properly synchronized. The attacker would need access to the same ActiveAdmin application as the victim, and could exploit the issue by timing their request immediately before when they know someone else will request a CSV (e.g. via phishing) or request CSVs frequently and hope someone else makes a concurrent request. PatchesVersions 2.12.0 and above fixed the problem by completely removing the shared state. Affected versions
0.1.0
0.1.1
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
+ 49 more Show less
0.4.2
0.4.3
0.4.4
0.5.0
0.5.0.pre
0.5.0.pre1
0.5.1
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
1.0.0
1.0.0.pre1
1.0.0.pre2
1.0.0.pre3
1.0.0.pre4
1.0.0.pre5
1.1.0
1.2.0
1.2.1
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
2.0.0
2.0.0.rc1
2.0.0.rc2
2.1.0
2.10.0
2.10.1
2.11.0
2.11.1
2.11.2
2.2.0
2.3.0
2.3.1
2.4.0
2.5.0
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
Fixed in
2.12.0
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|