CVE-2026-33202
Last modified
CVE-2026-33202 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rubyonrails | Rails | < 7.2.3.1 |
| Rubyonrails | Rails | >= 8.0.0, < 8.0.4.1 |
| Rubyonrails | Rails | >= 8.1.0, < 8.1.2.1 |
References
- https://github.com/rails/rails/releases/tag/v7.2.3.1Release Notes
- https://github.com/rails/rails/releases/tag/v8.0.4.1Release Notes
- https://github.com/rails/rails/releases/tag/v8.1.2.1Release Notes
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-33202?
How severe is CVE-2026-33202?
How do I fix CVE-2026-33202?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-33192Free5GC is an open-source Linux Foundation project for 5th g…5.3
- CVE-2026-33193Docmost is open-source collaborative wiki and documentation …4.6
- CVE-2026-33194SiYuan is a personal knowledge management system. Prior to v…6.8
- CVE-2026-33195Active Storage allows users to attach cloud and local files …9.8
- CVE-2026-3320Reflected Cross-Site Scripting (XSS) in the latest demo vers…5.1
- CVE-2026-33201Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., L…7
- CVE-2026-33203SiYuan is a personal knowledge management system. Prior to v…7.5
- CVE-2026-33204SimpleJWT is a simple JSON web token library written in PHP.…7.5
- CVE-2026-33205calibre is a cross-platform e-book manager for viewing, conv…5.5
- CVE-2026-33206calibre is a cross-platform e-book manager for viewing, conv…6.3
- CVE-2026-33207DataEase is an open-source data visualization and analytics …8.8
- CVE-2026-33208Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…8.8
Are you affected by CVE-2026-33202?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
