Rails Active Storage has possible glob injection in its DiskService
Modified: 9/10/2026
package
pkg:rubygems/activestorage
Rails Active Storage has possible glob injection in its DiskService
Modified: 9/10/2026
Exposure of Sensitive Information to an Unauthorized Actor in activestorage
Modified: 2/22/2024
Rails has possible Sensitive Session Information Leak in Active Storage
Modified: 9/10/2026
Rails Active Storage has possible Path Traversal in DiskService
Modified: 9/10/2026
Circumvention of file size limits in ActiveStorage
Modified: 2/22/2024
Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests
Modified: 9/10/2026
Rails Active Storage has possible content type bypass via metadata in direct uploads
Modified: 9/10/2026
Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests
Modified: 9/10/2026
Active Storage allowed transformation methods that were potentially unsafe
Modified: 1/31/2026
Possible code injection vulnerability in Rails / Active Storage
Modified: 3/13/2026
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
Modified: 9/10/2026