rising3월 24일· 2 sources
CVE-2026-33195: CVE-2026-33195: Path Traversal Vulnerability in Ruby on Rails Active Storage DiskService
CVE-2026-33195: Ruby on Rails Active Storage DiskService 경로 탐색(Path Traversal) 취약점
Why it matters
CVE-2026-33195 is a high-severity (CVSS 8.0) path traversal vulnerability in Ruby on Rails Active Storage's DiskService component that allows unauthenticated attackers to read, write, and delete arbitrary files when user-controllable blob keys are permitted. Patches have been released in activestorage versions 7.2.3.1, 8.0.4.1, and 8.1.2.1, and users are advised to upgrade immediately and audit custom implementations.
2
Sources
+0
24h
—
Growth
181d
Active
active storageactivesupportcve-2026-33169cve-2026-33195diskservicenumber_to_delimitedpath traversalredosruby on rails