CVE-2026-33202 PUBLISHED

Rails Active Storage has possible glob injection in its DiskService

Assigner: GitHub_M
Reserved: 17.03.2026 Published: 23.03.2026 Updated: 24.03.2026

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's DiskService#delete_prefixed passes blob keys directly to Dir.glob without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
CVSS Score: 6.6

Product Status

Vendor rails
Product activestorage
Versions
  • Version >= 8.1.0.beta1, < 8.1.2.1 is affected
  • Version >= 8.0.0.beta1, < 8.0.4.1 is affected
  • Version < 7.2.3.1 is affected

References

Problem Types

  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE