CVE Database
/

CVE-2026-33195

Back to search

CVE-2026-33195

Published: Mar 23, 2026

Modified: Mar 25, 2026

PUBLISHED

Description

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

VendorProductVersions

rails

activestorage

affected
>= 8.1.0.beta1, < 8.1.2.1
affected
>= 8.0.0.beta1, < 8.0.4.1
affected
< 7.2.3.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now