CVE-2026-33195: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2026-33195 is a path traversal vulnerability in Ruby on Rails Active Storage's DiskService#path_for method that fails to validate that resolved filesystem paths remain within the configured storage root directory. Discovered by HackerOne researcher ksw9722 and disclosed on March 23, 2026, it affects Rails versions before 7.2.3.1, 8.0.0–8.0.4.1 (exclusive), and 8.1.0–8.1.2.1 (exclusive). The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, though the GitHub advisory rates it as Low severity, reflecting that exploitation requires an application to pass untrusted user input as blob keys — a non-default pattern (GitHub Advisory, Feedly).

Technical details

The root cause (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) lies in the original DiskService#path_for implementation, which simply called File.join(root, folder_for(key), key) without verifying the resulting path stayed within the storage root. An attacker who can control the blob key value can supply path traversal sequences such as ../../etc/passwd or null bytes, causing the resolved path to escape the intended storage directory. The fix adds two layers of defense: first, rejecting keys containing dot segments (. or ..) or null bytes; second, verifying via File.expand_path that the resolved path starts with the storage root prefix before proceeding with any filesystem operation (Rails Commit, GitHub Advisory). Exploitation requires the application to pass user-supplied input directly as a blob key to Active Storage's DiskService — blob keys are documented as trusted strings, so only applications that deviate from this expectation are affected.

Impact

Successful exploitation allows an attacker to read, write, or delete arbitrary files on the server accessible to the Rails process, including sensitive system files such as /etc/passwd, /etc/shadow, application credentials, or private keys. Write access could enable an attacker to plant malicious files (e.g., web shells or cron jobs), while delete operations could cause denial of service by removing critical application or system files. The vulnerability affects confidentiality, integrity, and availability of the host system, and could facilitate lateral movement if credentials or SSH keys are exposed (GitHub Advisory, Feedly).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.025% (0.000250), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on an application passing untrusted user input as Active Storage blob keys, which limits the attack surface to a subset of Rails applications using DiskService with custom key handling.

Exploitation steps

  1. Identify target application: Locate a Ruby on Rails application using Active Storage with the DiskService backend (local disk storage) that accepts user-controlled input as blob keys — for example, a file upload endpoint where the key parameter is derived from user input.
  2. Craft a malicious blob key: Construct a key containing path traversal sequences, such as ../../etc/passwd, ../../../../../etc/shadow, or a null-byte variant like validkey\x00.jpg, designed to resolve outside the storage root directory.
  3. Submit the traversal key: Pass the malicious key to the application via the relevant API or form parameter that feeds into ActiveStorage::Blob.create_and_upload! or a similar method with the key: argument.
  4. Trigger file read/write/delete: Depending on the operation invoked (download, upload, or delete), the DiskService#path_for method resolves the traversal path and performs the filesystem operation on the target file outside the storage root.
  5. Exfiltrate or manipulate data: Read sensitive files (e.g., credentials, private keys), overwrite critical files (e.g., cron jobs, authorized_keys), or delete files to cause denial of service (GitHub Advisory, Rails Commit).

Indicators of compromise

  • Logs: Rails application logs showing ActiveStorage::InvalidKeyError exceptions (on patched systems detecting attempted exploitation); access log entries with blob key parameters containing ../, ..%2F, %2e%2e, or null bytes (%00).
  • File System: Unexpected files created or modified outside the Active Storage root directory (e.g., in /etc/, /tmp/, or application config directories) with timestamps correlating to application activity; missing or altered system files such as /etc/passwd or /etc/cron.d/ entries.
  • Network: Unusual HTTP requests to Active Storage disk service endpoints (/rails/active_storage/disk/) with encoded path traversal sequences in key parameters.
  • Process: Unexpected child processes spawned by the Rails server process accessing files outside the web application directory tree.

Mitigation and workarounds

Upgrade Rails to the patched versions: 7.2.3.1 (for 7.x), 8.0.4.1 (for 8.0.x), or 8.1.2.1 (for 8.1.x) (Rails v7.2.3.1 Release, GitHub Advisory). As an immediate workaround, audit all code paths that pass values to Active Storage's key: parameter and ensure no user-supplied input reaches these arguments without strict allowlist validation. Additionally, apply OS-level filesystem access controls (e.g., chroot, AppArmor, or SELinux policies) to restrict the Rails process to only the directories it legitimately needs, limiting the blast radius of any path traversal attempt. IBM products including Aspera Faspex 5, Cloud Pak for AIOps, and License Metric Tool v9 are also affected and have separate vendor advisories (IBM Aspera Advisory, IBM CloudPak Advisory).

Community reactions

The Rails team published a security release announcement on March 23, 2026, bundling CVE-2026-33195 with several other CVEs fixed in the same patch releases (Rails Release Blog). The vulnerability was responsibly disclosed via HackerOne by researcher ksw9722 and credited to Mike Dalessio for the fix implementation (GitHub Advisory). Community discussion noted the conditional nature of the vulnerability — requiring non-default application behavior of passing user input as blob keys — which contributed to the advisory's "Low" severity rating despite the high CVSS score. Red Hat also tracked the issue and IBM issued downstream advisories for affected products.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rails

Affected

sid

rails: 2:7.2.3.1+dfsg-1

Fixed

trixie

rails

Affected

Ubuntu

Unknown

bionic (esm-apps)

rails

Unknown

devel

rails

Unknown

focal (esm-apps)

rails

Unknown

jammy

rails

Unknown

jammy (esm-apps)

rails

Unknown

noble

rails

Unknown

noble (esm-apps)

rails

Unknown

resolute

rails

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management