VDB
Sign up
MEDIUM

GHSA-76r7-hhxj-r776

Active Record logging vulnerable to ANSI escape injection

Quick fix

GHSA-76r7-hhxj-r776 — activerecord: upgrade to the fixed version with the command below.

bundle update activerecord

Details

This vulnerability has been assigned the CVE identifier CVE-2025-55193

### Impact The ID passed to `find` or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences.

### Releases The fixed releases are available at the normal locations.

### Credits

Thanks to [lio346](https://hackerone.com/lio346) from Unit 515 of OPSWAT for reporting this vulnerability

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/activerecord
Introduced in: 8.0Fixed in: 8.0.2.1
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 7.2Fixed in: 7.2.2.2
Fixbundle update activerecord
RubyGems/activerecord
Introduced in: 0Fixed in: 7.1.5.2
Fixbundle update activerecord

References