MEDIUM
GHSA-76r7-hhxj-r776
Active Record logging vulnerable to ANSI escape injection
Quick fix
GHSA-76r7-hhxj-r776 — activerecord: upgrade to the fixed version with the command below.
bundle update activerecordDetails
This vulnerability has been assigned the CVE identifier CVE-2025-55193
### Impact The ID passed to `find` or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences.
### Releases The fixed releases are available at the normal locations.
### Credits
Thanks to [lio346](https://hackerone.com/lio346) from Unit 515 of OPSWAT for reporting this vulnerability
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rails/rails/security/advisories/GHSA-76r7-hhxj-r776[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-55193[ADVISORY]
- https://github.com/rails/rails/commit/3beef20013736fd52c5dcfdf061f7999ba318290[WEB]
- https://github.com/rails/rails/commit/568c0bc2f1e74c65d150a84b89a080949bf9eb9b[WEB]
- https://github.com/rails/rails/commit/6a944ca4805e72050a0fbb1a461534eb760d3202[WEB]
- https://github.com/rails/rails[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2025-55193.yml[WEB]