Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the …
Critical CVSS 9.8
Summary
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/rails/rails/commit/4933c1e3b8c1bb04925d60347be9f69270392f2c Patch
- https://github.com/rails/rails/commit/9b06fbc0f504b8afe333f33d19548f3b85fbe655 Patch
- https://github.com/rails/rails/commit/a290c8a1ec189d793aa6d7f2570b6a763f675348 Patch
- https://github.com/rails/rails/releases/tag/v7.2.3.1 Release Notes
- https://github.com/rails/rails/releases/tag/v8.0.4.1 Release Notes
- https://github.com/rails/rails/releases/tag/v8.1.2.1 Release Notes
- https://github.com/rails/rails/security/advisories/GHSA-9xrj-h377-fr87 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-33195
- https://bugzilla.redhat.com/show_bug.cgi?id=2450546
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33195.json
Timeline
- nvd_ingest NVD