Sidekiq-Cron Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Sidekiq-Cron versions through 2.3.1. This issue allows an attacker to execute malicious scripts by sending a crafted URL that is processed by the Sidekiq-Cron 'admin' web UI. The vulnerability could be exploited to steal cookies, session data, or local storage information from the application where the Sidekiq-Cron web UI is active.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute scripts in the context of the user's session.

Reproduction

To reproduce this vulnerability, send a GET request to the Sidekiq-Cron 'admin' web UI with crafted parameters that include malicious JavaScript. This can be done by embedding the script in HTML tags, such as an image tag with an 'onerror' event. The malicious script will be executed when the link is clicked, demonstrating the cross-site scripting vulnerability.

Remediation

Users can update to Sidekiq-Cron version 2.4.0, which addresses this vulnerability by fixing the underlying issue and removing the ability to inject malicious scripts.

Added: May 7, 2026, 3:53 PM
Updated: May 7, 2026, 3:53 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.4
exploitability
7.5
remediation
0.0
relevance
7.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.