
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33195 is a path traversal vulnerability in Ruby on Rails Active Storage's DiskService#path_for method that fails to validate that resolved filesystem paths remain within the configured storage root directory. Discovered by HackerOne researcher ksw9722 and disclosed on March 23, 2026, it affects Rails versions before 7.2.3.1, 8.0.0–8.0.4.1 (exclusive), and 8.1.0–8.1.2.1 (exclusive). The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, though the GitHub advisory rates it as Low severity, reflecting that exploitation requires an application to pass untrusted user input as blob keys — a non-default pattern (GitHub Advisory, Feedly).
The root cause (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) lies in the original DiskService#path_for implementation, which simply called File.join(root, folder_for(key), key) without verifying the resulting path stayed within the storage root. An attacker who can control the blob key value can supply path traversal sequences such as ../../etc/passwd or null bytes, causing the resolved path to escape the intended storage directory. The fix adds two layers of defense: first, rejecting keys containing dot segments (. or ..) or null bytes; second, verifying via File.expand_path that the resolved path starts with the storage root prefix before proceeding with any filesystem operation (Rails Commit, GitHub Advisory). Exploitation requires the application to pass user-supplied input directly as a blob key to Active Storage's DiskService — blob keys are documented as trusted strings, so only applications that deviate from this expectation are affected.
Successful exploitation allows an attacker to read, write, or delete arbitrary files on the server accessible to the Rails process, including sensitive system files such as /etc/passwd, /etc/shadow, application credentials, or private keys. Write access could enable an attacker to plant malicious files (e.g., web shells or cron jobs), while delete operations could cause denial of service by removing critical application or system files. The vulnerability affects confidentiality, integrity, and availability of the host system, and could facilitate lateral movement if credentials or SSH keys are exposed (GitHub Advisory, Feedly).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.025% (0.000250), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on an application passing untrusted user input as Active Storage blob keys, which limits the attack surface to a subset of Rails applications using DiskService with custom key handling.
../../etc/passwd, ../../../../../etc/shadow, or a null-byte variant like validkey\x00.jpg, designed to resolve outside the storage root directory.ActiveStorage::Blob.create_and_upload! or a similar method with the key: argument.DiskService#path_for method resolves the traversal path and performs the filesystem operation on the target file outside the storage root.ActiveStorage::InvalidKeyError exceptions (on patched systems detecting attempted exploitation); access log entries with blob key parameters containing ../, ..%2F, %2e%2e, or null bytes (%00)./etc/, /tmp/, or application config directories) with timestamps correlating to application activity; missing or altered system files such as /etc/passwd or /etc/cron.d/ entries./rails/active_storage/disk/) with encoded path traversal sequences in key parameters.Upgrade Rails to the patched versions: 7.2.3.1 (for 7.x), 8.0.4.1 (for 8.0.x), or 8.1.2.1 (for 8.1.x) (Rails v7.2.3.1 Release, GitHub Advisory). As an immediate workaround, audit all code paths that pass values to Active Storage's key: parameter and ensure no user-supplied input reaches these arguments without strict allowlist validation. Additionally, apply OS-level filesystem access controls (e.g., chroot, AppArmor, or SELinux policies) to restrict the Rails process to only the directories it legitimately needs, limiting the blast radius of any path traversal attempt. IBM products including Aspera Faspex 5, Cloud Pak for AIOps, and License Metric Tool v9 are also affected and have separate vendor advisories (IBM Aspera Advisory, IBM CloudPak Advisory).
The Rails team published a security release announcement on March 23, 2026, bundling CVE-2026-33195 with several other CVEs fixed in the same patch releases (Rails Release Blog). The vulnerability was responsibly disclosed via HackerOne by researcher ksw9722 and credited to Mike Dalessio for the fix implementation (GitHub Advisory). Community discussion noted the conditional nature of the vulnerability — requiring non-default application behavior of passing user input as blob keys — which contributed to the advisory's "Low" severity rating despite the high CVSS score. Red Hat also tracked the issue and IBM issued downstream advisories for affected products.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."