stimulus_reflex
Build reactive applications with the Rails tooling you already know and love.
Activity
- Latest release
- 1y ago
- Total releases
- 93
- Cadence
- ~8 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Oct 14, 2018
| Version | Released | |
|---|---|---|
3.5.5
patch
|
3.5.5
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.5.4
patch
|
3.5.4
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.5.3
patch
|
3.5.3
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
3.5.2
patch
|
3.5.2
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
3.5.1
patch
|
3.5.1
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
3.5.0
minor
|
3.5.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
3.4.2
patch
| ||
3.5.0.rc4
pre
|
3.5.0.rc4
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.5.0.rc3
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.5.0.rc3
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.5.0.rc2
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.5.0.rc2
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.5.0.rc1
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.5.0.rc1
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.5.0.pre10
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.5.0.pre10
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.5.0.pre9
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.5.0.pre9
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
3.5.0.pre8
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev |
3.5.0.pre8
pre
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
3.5.0.pre7
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.0.pre6
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.0.pre5
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.0.pre4
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.0.pre3
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.0.pre2
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.0.pre1
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.0.pre0
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.1
patch
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0
minor
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre9
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre8
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre7
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre6
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre5
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre4
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre3
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre2
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre1
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0.pre0
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0.pre6
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0.pre5
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0.pre4
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0.pre3
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0.pre2
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0.pre1
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.3.0.pre0
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.3
patch
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.2
patch
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.2.pre1
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.2.pre0
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.1
patch
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.0.pre1
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.2.0.pre0
pre
1 CVE
CVE-2024-28121
GHSA-f78j-4w3g-4q65
Mar 12, 2024
StimulusReflex arbitrary method call
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryMore methods than expected can be called on reflex instances. Being able to call some of them has security implications. DetailsTo invoke a reflex a websocket message of the following shape is sent:
The server will proceed to instantiate
This is problematic as This variable can be overwritten using the following message:
Here are other interesting methods that were found to be available for the ChatReflex sample reflex
All in all, only counting
Using
Pre-versions of 3.5.0 added a
PatchesPatches are available on RubyGems and on NPM. The patched versions are: WorkaroundYou can add this guard to mitigate the issue if running an unpatched version of the library. 1.) Make sure all your reflexes inherit from the
Affected versions
3.5.0.pre0
3.5.0.pre1
3.5.0.pre10
3.5.0.pre2
3.5.0.pre3
3.5.0.pre4
3.5.0.pre5
3.5.0.pre6
3.5.0.pre7
3.5.0.pre8
3.5.0.pre9
3.5.0.rc1
+ 73 more Show less
3.5.0.rc2
3.5.0.rc3
0.1.0
0.1.1
0.1.10
0.1.12
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.3.1
0.3.2
0.3.3
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
3.0.0
3.1.2
3.1.3
3.1.4
3.2.0
3.2.0.pre0
3.2.0.pre1
3.2.1
3.2.2
3.2.2.pre0
3.2.2.pre1
3.2.3
3.3.0
3.3.0.pre0
3.3.0.pre1
3.3.0.pre2
3.3.0.pre3
3.3.0.pre4
3.3.0.pre5
3.3.0.pre6
3.4.0
3.4.0.pre0
3.4.0.pre1
3.4.0.pre2
3.4.0.pre3
3.4.0.pre4
3.4.0.pre5
3.4.0.pre6
3.4.0.pre7
3.4.0.pre8
3.4.0.pre9
3.4.1
Fixed in
3.4.2
3.5.0.rc4
References
Updated Sep 10, 2026 · Source: OSV.dev |