secure_headers
Add easily configured security headers to responses including content-security-policy, x-frame-options, strict-transport-security, etc.
Activity
- Latest release
- 3mo ago
- Total releases
- 114
- Cadence
- ~15 days
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Feb 13, 2013
| Version | Released | |
|---|---|---|
7.3.0
minor
| ||
7.2.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
7.1.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
7.0.0
major
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.6.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.7.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.5.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.4.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.3.4
patch
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.3.3
patch
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.3.2
patch
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.3.1
patch
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.9.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
5.1.0
minor
2 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.3.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.2.0
minor
2 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
5.2.0
minor
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.8.0
minor
2 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.7.4
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.1.2
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.1.1
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.1.0
minor
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.0.0
major
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.0.0.alpha03
pre
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.0.0.alpha02
pre
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
6.0.0.alpha01
pre
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
5.0.5
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
5.0.4
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
5.0.3
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
5.0.2
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
5.0.1
major
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
4.0.2
patch
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.7.3
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
5.0.0.alpha01
pre
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
4.0.1
patch
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.7.2
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
4.0.0
major
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
4.0.0.alpha04
pre
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.7.1
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.7.0
minor
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
4.0.0.alpha02
pre
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
4.0.0.alpha03
pre
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
4.0.0.alpha01
pre
1 CVE
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.6.7
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.6.6
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.6.5
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.6.4
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.6.3
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.6.2
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
| ||
3.6.1
patch
3 CVEs
CVE-2026-54163
GHSA-rqq5-2gf9-4w4q
Jul 10, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
4.7
/ 10
Medium
Network
High
None
Required
Changed
Low
Low
None
Summary
When an application forwards untrusted input into An existing ImpactAlthough piping untrusted input into CSP directives is generally discouraged, applications that do so for one of the three uncovered directives turn that endpoint into an XSS sink with an effective The global default CSP set in Affected
Applications that set Mitigations / WorkaroundsUntil upgrading to 7.3.0, sanitize any user-controlled input before passing it to:
for Vulnerable codeThree sibling builders all join an attacker-controllable value into the CSP header value with no
For comparison, Validation also does not catch it:
ReachableThe three sinks are reached by the documented public override APIs in Concrete reachable shapes:
In all three patterns, a string field that the app expects to be a single token ( Proof of conceptPinned reproduction against a minimal Rack app on Install (Bundler):
Driver (
Run:
End-to-end reproduction against
|