Ruby Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-0256
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1 as used in Ruby does not properly generate documents which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.