CVE-2025-24293Disclosure

LOWCVSS 9.2 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: ``` <%= image_tag blob.variant(params[:t] => params[:v]) %> ``` Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds ----------- Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong [ImageMagick security policy](https://imagemagick.org/script/security-policy.php) deployed. Credits ------- Thank you [lio346](https://hackerone.com/lio346) for reporting this!

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-94CWE-88

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-31); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-01-30: 2Mentions · 2026-07-30: 1Mentions · 2026-07-31: 3Mentions · 2026-08-04: 1PoC Mentioned / Linked · 2026-07-31: 1PoC Mentioned / Linked · 2026-08-04: 1Exploit Tool / Code · 2026-07-31: 1Technical Details · 2026-01-30: 1Technical Details · 2026-07-30: 1Technical Details · 2026-07-31: 3Technical Details · 2026-08-04: 101-3007-3007-3108-04
Signal classification3 categories
Disclosure
571.4%
General
114.3%
PoC
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-302
Disclosure1General1
2026-07-301
Disclosure1
2026-07-313
Disclosure2PoC1
2026-08-041
Disclosure1
Full discourse7 posts
  • The Hacker News@TheHackersNews
    PoC

    🚨 New from Ethiack: A crafted MATLAB/HDF5 upload can make Rails Active Storage read server secrets. Attackers could then use a stolen secret_key_base to forge a variation key and reach RCE via CVE-2025-24293. Rails also released a forensic toolkit to check exposure and hunt for exploitation. Read the updated story: https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html

    Post summary

    A PoC using a crafted MATLAB/HDF5 file demonstrates that CVE‑2025‑24293 allows attackers to read Rails secrets and achieve RCE, though no active exploitation is reported.

    5141621424.2K
    2.4M followersView on X
  • Sam Stones(Hunter)👨‍💻@SamTechwest
    Disclosure

    🚨 New from Ethiack: A crafted MATLAB/HDF5 upload can make Rails Active Storage read server secrets. Attackers could then use a stolen secret_key_base to forge a variation key and reach RCE via CVE-2025-24293. Is offensive still a joke to you. 🤣🤣🤣🤣 https://t.co/IPjQBEHTdO

    Post summary

    The tweet announces a new exploitation method for CVE-2025-24293 involving MATLAB/HDF5 uploads that can expose Rails secret keys and lead to remote code execution, but provides no evidence of active attacks, patches, or a PoC.

    0001091
    767 followersView on X
  • ROHIT@rynosec
    Disclosure

    ⚡ Active Storage Vips Transformer Missing validate_transformation — CVE-2025-24293 Incomplete Fix 👨🏻‍💻 friedchicken112211 ➟ Ruby on Rails 🟥 High 💰 None 🔗 https://hackerone.com/reports/3553340 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/N4K65mneeS

    Post summary

    The tweet announces a new CVE (CVE-2025-24293) concerning a missing validation in Rails' Active Storage Vips Transformer and links to a HackerOne report without providing exploit code or patch details.

    00010311
    7.0K followersView on X
  • BT Haberler@BTHaberler
    Disclosure

    Ruby on Rails'te CVSS 9.5 Kritik Açık, Dosya Okuma RCE'ye Kadar Uzanıyor Ruby on Rails'in Active Storage bileşenindeki bir açık, saldırganların sunucudan gizli anahtarları çalıp uzaktan kod çalıştırmasına kadar uzanan bir saldırı zincirine kapı açıyor! • CVE-2026-66066 olarak kayıtlı açık (CVSS 9.5), Active Storage'ın libvips ile güvenilmeyen görüntü işlemlerini engellemeyişinden kaynaklanıyor; saldırgan "MATLAB 5.0" başlığıyla maskelenmiş ve HDF5 dış veri setine işaret eden özel hazırlanmış MAT dosyaları yükleyebiliyor. • Bu teknik, Rails işlem ortamından secret_key_base dahil kimlik bilgilerinin okunmasını sağlıyor; bu da daha önceki CVE-2025-24293 ile birleştiğinde uzaktan kod çalıştırmaya kadar uzanabiliyor. • Açık Rails 6.1, 7.0-7.2 ve 8.0-8.1 serilerinin geniş bir bölümünü etkiliyor; resmi PoC yayınlanmasa da üçüncü taraf bir depo, loopback Docker ortamında tam istismar zincirini gösterdiğini iddia ediyor. Rails gibi yaygın kullanılan bir framework'te dosya işleme katmanından RCE'ye uzanan bu tür zincirler, milyonlarca üretim uygulamasını doğrudan ilgilendiriyor. #SiberGüvenlik #RubyOnRails #RCE

    Post summary

    CVE‑2026‑66066 is a high‑severity RCE flaw in Rails Active Storage that allows attackers to read secret keys and, combined with CVE‑2025‑24293, execute code via crafted MAT files. A third‑party PoC demonstrates the full exploit chain, but no patch or active exploitation is reported.

    0000089
    38 followersView on X
  • NeoTeo.com@NeoteoCom
    Disclosure

    Ethiack descubrió que un archivo MATLAB/HDF5 en Rails Active Storage puede leer secretos del servidor y escalar a RCE vía CVE-2025-24293. https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html

    Post summary

    Ethiack reported that a MATLAB/HDF5 file handled by Rails Active Storage can read server secrets and lead to a remote code execution via CVE-2025-24293.

    00000120
    15.9K followersView on X
  • CVE@CVEnew
    General

    CVE-2025-24293 # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods a… https://www.cve.org/CVERecord?id=CVE-2025-24293

    Post summary

    The text notes the CVE-2025-24293 concerning potentially unsafe image transformation methods in Active Storage but provides no further technical details, exploitation evidence, or mitigation information.

    00000184
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-24293: Rails (CVSS: 9.2)... Command injection lurks in Rails Active Storage when user input feeds transformation methods - three whitelisted method... https://zerodaysignal.com/vulnerability/CVE-2025-24293 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text discloses a high‑severity command injection vulnerability in Rails Active Storage, specifying its nature and CVSS score but lacking evidence of active exploitation or mitigation.

    0000057
    132 followersView on X

Explore more