CVE-2026-33195General(rubyonrails / rails)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch rubyonrails rails systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rails

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-24)
  • 4 total mentions across 2 days

Affected systems

Products
rails

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-23: 1Mentions · 2026-03-24: 3Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 103-2303-24
Signal classification3 categories
General
250.0%
Patch
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-231
Patch1
2026-03-243
Disclosure1General2
Full discourse4 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33195 📊 Severity: 8.0 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33195 #CVE-2026-33195 #CVE #High #CyberSecurity #InfoSec https://t.co/q4Nz4qLgsc

    Post summary

    The tweet announces CVE-2026-33195 with a severity score of 8.0 and indicates it affects multiple unspecified products, but provides no further technical, exploit, or mitigation details.

    0000028
    111 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33195 Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path… https://www.cve.org/CVERecord?id=CVE-2026-33195

    Post summary

    The post cites CVE‑2026‑33195 affecting certain Rails versions but gives no exploit details, patch info, or technical specifics.

    00000151
    56.8K followersView on X
  • TRONCAL Yannick@ytroncal
    Disclosure

    CVE-2026-33195: CVE-2026-33195: Path Traversal Vulnerability in Ruby on Rails Active Storage DiskService https://dev.to/cverports/cve-2026-33195-cve-2026-33195-path-traversal-vulnerability-in-ruby-on-rails-active-storage-57me

    Post summary

    The post announces a path‑traversal flaw in Rails Active Storage DiskService and points to a detailed blog article, without providing evidence of exploitation or remediation.

    0000030
    140 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Ruby on Rails v7.2.3.1 がリリースされました。 📦 種別: patch ✨ 主な変更点: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) ⚠️ 破壊的変更: • `DiskService#delete_prefixed`の変更により、既存のグロブメタ文字展開に依存するコードは動作しなくなります。 🔧 重要な修正: • Active Support: NumberConverterにおける指数表記を拒否するよう修正(CVE-2026-33176) • Active Support: `SafeBuffer#%` がunsafeステータスを保持するように修正(CVE-2026-33170) • Active Support: NumberToDelimitedConverterのパフォーマンスを改善(CVE-2026-33169) • Action View: タグヘルパーで空の属性名をスキップし、不正なHTML生成を回避(CVE-2026-33168) • Active Storage: DirectUploadControllerでユーザー提供のメタデータをフィルタリング(CVE-2026-33173) • Active Storage: 最大ストリーミングチャンクサイズを設定可能に(CVE-2026-33174) • Active Storage: 範囲リクエストを単一の範囲に制限(CVE-2026-33658) • Active Storage: `DiskService`におけるパストラバーサルを防止(CVE-2026-33195) • Active Storage: `DiskService#delete_prefixed`におけるグロブインジェクションを防止(CVE-2026-33202) #GitHub #Release #Ruby on Rails

    Post summary

    Ruby on Rails v7.2.3.1 has been released as a patch, addressing a series of CVEs with specific technical fixes.

    0000036
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprubyonrailsrails---

Explore more