Home

Description

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

PUBLISHED Reserved 2025-12-08 | Published 2026-05-07 | Updated 2026-05-08 | Assigner mitre

References

github.com/sidekiq-cron/sidekiq-cron/issues/569 exploit

github.com/sidekiq-cron/sidekiq-cron/issues/569

github.com/sidekiq-cron/sidekiq-cron/releases/tag/v2.4.0

cve.org (CVE-2025-67202)

nvd.nist.gov (CVE-2025-67202)

Download JSON