CVE-2025-24293: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2025-24293 is a command injection vulnerability in Ruby on Rails' Active Storage component, where the default allowed list of image transformation methods includes three entries (apply, loader, saver) that can be exploited to bypass safe defaults and execute arbitrary commands. It affects activestorage versions >= 5.2.0 up to (but not including) 7.1.5.2, 7.2.2.2, and 8.0.2.1. The vulnerability was disclosed on August 13, 2025, via a GitHub Security Advisory, and was reported by researcher lio346 via HackerOne. It carries a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, Feedly).

Technical details

The root cause is improper neutralization of special elements used in a command (CWE-77) and improper control of code generation (CWE-94). Active Storage maintains an allowlist of permitted image transformation methods for use with the image_processing gem and mini_magick processor; however, three methods — apply, loader, and saver — were included in this list despite enabling dangerous behaviors such as writing arbitrary files or loading custom coders/savers. When an application passes unsanitized user input directly as transformation method names or parameters (e.g., blob.variant(params[:t] => params[:v])), an attacker can leverage these methods to inject OS-level commands. The fix removes apply, loader, and saver from the allowed transformation list across all affected branches (GitHub Advisory, Patch Commit).

Impact

Successful exploitation enables remote code execution (RCE) with the privileges of the Rails application process, allowing an attacker to execute arbitrary OS commands, read or exfiltrate sensitive data, write files to the server (e.g., web shells), and potentially pivot laterally within the hosting environment. All three CIA triad dimensions are fully compromised: confidentiality (data theft), integrity (file writes, system manipulation), and availability (service disruption). The vulnerability only affects applications that use Active Storage with image_processing and mini_magick and that pass untrusted user input directly to image variant methods (GitHub Advisory, OPSWAT Blog).

Exploitability

A public proof-of-concept (PoC) has been reported, and exploitation has been documented by OPSWAT Unit 515, who independently discovered and analyzed the RCE capability (OPSWAT Blog). The vulnerability is network-exploitable with no authentication or user interaction required, though it requires the specific precondition of an application accepting arbitrary user input for image transformation parameters. The EPSS score is approximately 0.168%, indicating a relatively low but non-negligible probability of exploitation in the wild. No CISA KEV catalog listing has been identified at this time. Detection coverage is available via Qualys (QID 5005051, 6272479) and Nessus (plugins 269912, 279494, 280081) (Feedly).

Exploitation steps

  1. Reconnaissance: Identify Ruby on Rails applications using Active Storage with image_processing and mini_magick gems, targeting versions >= 5.2.0 and < 7.1.5.2 / 7.2.2.2 / 8.0.2.1. Look for endpoints that accept user-controlled image transformation parameters.
  2. Identify vulnerable endpoint: Find application routes or views that pass user-supplied parameters directly to blob.variant(), such as image_tag blob.variant(params[:t] => params[:v]).
  3. Craft malicious payload: Construct a request using one of the dangerous allowed methods (saver, loader, or apply) as the transformation key, with a malicious argument — for example, using saver with a -write argument to write a file: ?t=saver&v['-write']=/tmp/shell.rb.
  4. Trigger image processing: Submit the crafted HTTP request to the vulnerable endpoint, causing Active Storage to invoke mini_magick with the injected transformation method and parameters.
  5. Achieve code execution: The injected command is passed to ImageMagick/MiniMagick, resulting in arbitrary file writes or OS command execution with the privileges of the Rails application process, enabling reverse shell establishment, data exfiltration, or further lateral movement (GitHub Advisory, OPSWAT Blog).

Indicators of compromise

  • Network: Unusual HTTP requests to image variant endpoints containing parameters with values like saver, loader, or apply as transformation method names; outbound connections from the Rails application server to unknown external IPs.
  • Logs: Rails application logs showing blob.variant calls with unexpected or suspicious transformation method names (e.g., saver, loader, apply) and arguments containing paths or shell metacharacters; ImageMagick error logs referencing -write or unusual file paths.
  • File System: Unexpected files written to /tmp/ or web-accessible directories (e.g., .rb, .erb, .sh files); new or modified files in the Rails application directory not associated with a deployment.
  • Process: Unusual child processes spawned by the Rails/Puma/Unicorn process (e.g., /bin/sh, curl, wget, bash); ImageMagick (convert, mogrify) processes with suspicious arguments including -write or external URIs.

Mitigation and workarounds

Upgrade activestorage to one of the patched versions: 7.1.5.2, 7.2.2.2, or 8.0.2.1. The fix removes the dangerous transformation methods apply, loader, and saver from the default allowed list (Patch Commit). As an interim workaround, strictly validate and whitelist all user-supplied image transformation methods and parameters before passing them to Active Storage — passing arbitrary user input to blob.variant() is explicitly unsupported and dangerous. Additionally, deploy a hardened ImageMagick security policy to restrict dangerous operations at the ImageMagick level (GitHub Advisory).

Community reactions

The Rails core team published the advisory on August 13, 2025, alongside the release of patched versions 8.0.2.1, 7.2.2.2, and 7.1.5.2 (Rails Blog). OPSWAT Unit 515 published a detailed technical blog post documenting their independent discovery and RCE proof-of-concept (OPSWAT Blog). The vulnerability received coverage in The Hacker News weekly recap and generated discussion on Reddit's r/rails and r/rubyonrails communities, with community members noting the importance of never passing raw user input to image transformation methods (Greg Molnar Blog). Debian issued security advisories (DSA-6090-1 and DLA-4416-1) for the vulnerability, and Chef Supermarket 5.3.0 was released to address it as a downstream dependency.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rails: 2:6.1.7.10+dfsg-1~deb12u2

Fixed

sid

rails: 2:7.2.2.2+dfsg-1

Fixed

trixie

rails: 2:7.2.2.2+dfsg-2~deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

rails

Unknown

devel

rails

Unknown

focal (esm-apps)

rails

Unknown

jammy

rails

Unknown

jammy (esm-apps)

rails

Unknown

noble

rails

Unknown

noble (esm-apps)

rails

Unknown

resolute

rails

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management