Reflex arbitrary method call in stimulus_reflex
Published Mar 12, 2024
8.8
HIGHCVSS 3.1
EPSS 1.55%
Description
stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and passing them to Rails over real-time websockets. In affected versions more methods than expected can be called on reflex instances. Being able to call some of them has security implications. To invoke a reflex a websocket message of the following shape is sent: `\"target\":\"[class_name]#[method_name]\",\"args\":[]`. The server will proceed to instantiate `reflex` using the provided `class_name` as long as it extends `StimulusReflex::Reflex`. It then attempts to call `method_name` on the instance with the provided arguments. This is problematic as `reflex.method method_name` can be more methods that those explicitly specified by the developer in their reflex class. A good example is the instance_variable_set method. This vulnerability has been patched in versions 3.4.2 and 3.5.0.rc4. Users unable to upgrade should: see the backing GHSA advisory for mitigation advice.
Affected products
-
- Version < 3.4.2StatusaffectedConstraints-
- Version >= 3.5.0.rc1, < 3.5.0.rc4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Stimulusreflex | Stimulus Reflex | n/a |
|
- < 3.4.2
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
- 3.5.0
-
- Version 0StatusaffectedConstraints<3.4.2
- Version 3.5.0.rc1StatusaffectedConstraints<3.5.0.rc4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Stimulusreflex | Stimulus Reflex | n/a |
|
No Red Hat product state for this CVE.
stimulus_reflex
RubyGems
Introduced 3.5.0.pre0 Fixed 3.5.0.rc4stimulus_reflex
RubyGems
Introduced 0 Fixed 3.4.2stimulus_reflex
npm
Introduced 3.5.0-pre0 Fixed 3.5.0-rc4stimulus_reflex
npm
Introduced 0 Fixed 3.4.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| RubyGems | stimulus_reflex | 3.5.0.pre0 | 3.5.0.rc4 |
| RubyGems | stimulus_reflex | 0 | 3.4.2 |
| npm | stimulus_reflex | 3.5.0-pre0 | 3.5.0-rc4 |
| npm | stimulus_reflex | 0 | 3.4.2 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Mar 13, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.55% (0.01555) | 74.25th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.55% (0.01555) | 71.84th | v5 (v2026.06.15) |
| Dec 18, 2025 | 1.40% (0.01404) | 79.99th | v4 (v2025.03.14) |
| Nov 21, 2025 | 0.34% (0.00343) | 56.33th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.67% (0.02671) | 84.49th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.45% (0.00451) | 62.40th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.03% (0.02027) | 82.18th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.10% (0.05099) | 82.66th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.38% (0.01379) | 78.97th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 12.15th | v3 (v2023.03.01) |
| Jul 2, 2024 | 0.04% (0.00044) | 10.46th | v3 (v2023.03.01) |
| Mar 14, 2024 | 0.04% (0.00044) | 8.43th | v3 (v2023.03.01) |
| Mar 13, 2024 | 0.04% (0.00045) | 12.66th | v3 (v2023.03.01) |
References (10)
- http://seclists.org/fulldisclosure/2024/Mar/16 ExploitThird Party Advisory
- https://github.com/advisories/GHSA-f78j-4w3g-4q65 Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/stimulus_reflex/CVE-2024-28121.yml
- https://github.com/stimulusreflex/stimulus_reflex/blob/0211cad7d60fe96838587f159d657e44cee51b9b/app/channels/stimulus_reflex/channel.rb#L83 x_refsource_MISCTechnical Description
- https://github.com/stimulusreflex/stimulus_reflex/commit/538582d240439aab76066c72335ea92096cd0c7f x_refsource_MISCPatch
- https://github.com/stimulusreflex/stimulus_reflex/commit/d823d7348f9ca42eb6df25574f11974e4f5bc88c
- https://github.com/stimulusreflex/stimulus_reflex/releases/tag/v3.4.2 x_refsource_MISCProductRelease Notes
- https://github.com/stimulusreflex/stimulus_reflex/releases/tag/v3.5.0.rc4 x_refsource_MISCProductRelease Notes
- https://github.com/stimulusreflex/stimulus_reflex/security/advisories/GHSA-f78j-4w3g-4q65 x_refsource_CONFIRMExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-28121
Change history (0)
No recorded changes yet.