CVE-2026-33195
Last modified
CVE-2026-33195 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rubyonrails | Rails | < 7.2.3.1 |
| Rubyonrails | Rails | >= 8.0.0, < 8.0.4.1 |
| Rubyonrails | Rails | >= 8.1.0, < 8.1.2.1 |
References
- https://github.com/rails/rails/releases/tag/v7.2.3.1Release Notes
- https://github.com/rails/rails/releases/tag/v8.0.4.1Release Notes
- https://github.com/rails/rails/releases/tag/v8.1.2.1Release Notes
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-33195?
How severe is CVE-2026-33195?
How do I fix CVE-2026-33195?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-3319Reflected Cross-Site Scripting (XSS) in the latest demo vers…5.1
- CVE-2026-33190CoreDNS is a DNS server that chains plugins. In versions pri…7.5
- CVE-2026-33191Free5GC is an open-source Linux Foundation project for 5th g…8.6
- CVE-2026-33192Free5GC is an open-source Linux Foundation project for 5th g…5.3
- CVE-2026-33193Docmost is open-source collaborative wiki and documentation …4.6
- CVE-2026-33194SiYuan is a personal knowledge management system. Prior to v…6.8
- CVE-2026-3320Reflected Cross-Site Scripting (XSS) in the latest demo vers…5.1
- CVE-2026-33201Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., L…7
- CVE-2026-33202Active Storage allows users to attach cloud and local files …9.1
- CVE-2026-33203SiYuan is a personal knowledge management system. Prior to v…7.5
- CVE-2026-33204SimpleJWT is a simple JSON web token library written in PHP.…7.5
- CVE-2026-33205calibre is a cross-platform e-book manager for viewing, conv…5.5
Are you affected by CVE-2026-33195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
