CVE-2026-33202CRITICAL 9.1EPSS p46.1%

CVE-2026-33202CVE-2026-33202

Description

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS0.65% probability of exploitation · percentile 46.1% · 2026-06-19T12:03:05Z
Published2026-03-24
Last modified2026-03-24

Underlying weaknesses· 1

CWE-74

References

  1. https://github.com/rails/rails/commit/8c9676b803820110548cdb7523800db43bc6874c
  2. https://github.com/rails/rails/commit/955284d26e469a9c026a4eee5b21f0414ab0bccf
  3. https://github.com/rails/rails/commit/fa19073546360856e9f4dab221fc2c5d73a45e82
  4. https://github.com/rails/rails/releases/tag/v7.2.3.1
  5. https://github.com/rails/rails/releases/tag/v8.0.4.1
  6. https://github.com/rails/rails/releases/tag/v8.1.2.1
  7. https://github.com/rails/rails/security/advisories/GHSA-73f9-jhhh-hr5m

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-740%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-33195
CVE
Ruby on Rails Directory Traversal Vulnerability
CVE
CVE-2026-45230
CVE
CVE-2026-36726
CVE
CVE-2026-41009
CVE
CVE-2025-7643
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.