CVE-2026-53769 PUBLISHED

Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy

Assigner: GitHub_M
Reserved: 10.06.2026 Published: 04.09.2026 Updated: 04.09.2026

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_<field>? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS Score: 6.5

Product Status

Vendor avo-hq
Product avo
Versions
  • Version >= 2.28.0, < 3.32.0 is affected

References

Problem Types

  • CWE-862: Missing Authorization CWE
  • CWE-863: Incorrect Authorization CWE