Critical severity9.1NVD Advisory· Published Mar 24, 2026· Updated Jun 17, 2026
CVE-2026-33202
CVE-2026-33202
Description
Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's DiskService#delete_prefixed passes blob keys directly to Dir.glob without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
activestorageRubyGems | >= 8.1.0.beta1, < 8.1.2.1 | 8.1.2.1 |
activestorageRubyGems | >= 8.0.0.beta1, < 8.0.4.1 | 8.0.4.1 |
activestorageRubyGems | < 7.2.3.1 | 7.2.3.1 |
Affected products
12- osv-coords10 versionspkg:apk/chainguard/gitlab-rails-ce-18.10pkg:apk/chainguard/gitlab-rails-ce-18.8pkg:apk/chainguard/gitlab-rails-ce-18.9pkg:apk/chainguard/gitlab-rails-ce-fips-18.10pkg:apk/chainguard/gitlab-rails-ce-fips-18.9pkg:apk/chainguard/ruby3.2-rails-8.1pkg:apk/chainguard/ruby3.4-rails-8.0pkg:apk/wolfi/ruby3.2-rails-8.1pkg:apk/wolfi/ruby3.4-rails-8.0pkg:gem/activestorage
< 18.10.3-r1+ 9 more
- (no CPE)range: < 18.10.3-r1
- (no CPE)range: < 18.8.11-r4
- (no CPE)range: < 18.9.5-r0
- (no CPE)range: < 18.10.3-r0
- (no CPE)range: < 18.9.5-r0
- (no CPE)range: < 8.1.3-r0
- (no CPE)range: < 8.0.5-r0
- (no CPE)range: < 8.1.3-r0
- (no CPE)range: < 8.0.5-r0
- (no CPE)range: >= 8.1.0.beta1, < 8.1.2.1
- Range: >= 8.1.0.beta1, < 8.1.2.1
Patches
Vulnerability mechanics
References
10- github.com/rails/rails/commit/8c9676b803820110548cdb7523800db43bc6874cnvdPatchWEB
- github.com/rails/rails/commit/955284d26e469a9c026a4eee5b21f0414ab0bccfnvdPatchWEB
- github.com/rails/rails/commit/fa19073546360856e9f4dab221fc2c5d73a45e82nvdPatchWEB
- github.com/advisories/GHSA-73f9-jhhh-hr5mghsaADVISORY
- github.com/rails/rails/security/advisories/GHSA-73f9-jhhh-hr5mnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-33202ghsaADVISORY
- github.com/rails/rails/releases/tag/v7.2.3.1nvdRelease NotesWEB
- github.com/rails/rails/releases/tag/v8.0.4.1nvdRelease NotesWEB
- github.com/rails/rails/releases/tag/v8.1.2.1nvdRelease NotesWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-33202.ymlghsaWEB
News mentions
0No linked articles in our index yet.