CVE-2026-33168: Actionview Missing Blank Key Check
Action View tag helpers fail to correctly filter blank attribute names when iterating to build HTML options. An attacker controlling attribute keys could supply an empty string and bypass attribute quoting, leading to Cross-site Scripting (XSS).
greprules fetch cve-2026-33168-actionview-missing-blank-key-check --engine opengrepDescription
Action View tag helpers fail to correctly filter blank attribute names when iterating to build HTML options. An attacker controlling attribute keys could supply an empty string and bypass attribute quoting, leading to Cross-site Scripting (XSS).
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.