CVE-2026-33202: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2026-33202 is a glob injection vulnerability in Rails Active Storage's DiskService#delete_prefixed method that can allow deletion of unintended files from the storage directory. It affects all Rails versions prior to 7.2.3.1, 8.0.4.1, and 8.1.2.1 (specifically the activestorage gem). The vulnerability was disclosed on March 23, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 9.1 (Critical) and a CVSS v4.0 base score of 6.6 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is improper neutralization of special elements (CWE-74) combined with path traversal concerns (CWE-22): the DiskService#delete_prefixed method passes blob keys directly to Dir.glob without escaping glob metacharacters such as *, ?, [, ], {, and }. When Blob#delete is called, it invokes delete_prefixed with a string containing the blob key, which is then interpolated into a glob pattern ("#{prefix}*") and passed to Dir.glob. If an attacker can influence blob key generation — either through direct untrusted input or custom key schemes — they can craft keys containing glob metacharacters to match and delete files beyond the intended target. The fix introduces a private escape_glob_metacharacters method that escapes these characters before the glob is evaluated (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation allows an attacker to delete arbitrary files within the Active Storage disk service's storage directory, beyond the intended blob. This can result in data loss, deletion of critical application files, and service disruption. The attack requires no authentication, no special privileges, and no user interaction, making it broadly accessible in scenarios where blob key input is attacker-influenced. Confidentiality is not directly impacted, but integrity and availability are both rated High (Feedly, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on the attacker being able to control or influence blob key generation, which limits the practical attack surface in well-configured applications.

Exploitation steps

  1. Identify target: Determine that the Rails application uses Active Storage with the DiskService backend (local disk storage) and is running a vulnerable version (prior to 7.2.3.1, 8.0.4.1, or 8.1.2.1).
  2. Gain influence over blob keys: Find an application feature that allows user-controlled or externally-influenced input to be used as a blob key — for example, a file upload endpoint where the key is derived from user-supplied metadata or filenames.
  3. Craft a malicious blob key: Construct a key containing glob metacharacters (e.g., *, ?, [, ], {, }) designed to match unintended files in the storage directory. For example, a key like ab/cd/[a-z]* would expand to match multiple files beyond the intended target.
  4. Trigger blob deletion: Cause the application to call Blob#delete (or DiskService#delete_prefixed directly) on the crafted blob key, which passes the unescaped key to Dir.glob, matching and deleting unintended files via FileUtils.rm_rf.
  5. Achieve impact: Unintended files in the storage directory are deleted, potentially causing data loss or service disruption (GitHub Commit, GitHub Advisory).

Indicators of compromise

  • Logs: Application logs showing blob deletion events (delete_prefixed instrumentation) with keys containing glob metacharacters (*, ?, [, ], {, }); unexpected mass file deletion events in Active Storage logs.
  • File System: Missing files in the Active Storage disk service root directory that were not explicitly deleted by the application; unexpected gaps in stored blob files.
  • Application Behavior: Errors or exceptions related to missing blobs that were not intentionally removed; unexpected ActiveStorage::FileNotFoundError or similar errors for blobs that should exist.

Mitigation and workarounds

Upgrade Rails Active Storage to the patched versions: 7.2.3.1, 8.0.4.1, or 8.1.2.1, depending on the currently installed branch (GitHub Release, GitHub Advisory). If immediate patching is not possible, implement strict input validation and sanitization to reject blob keys containing glob metacharacters (*, ?, [, ], {, }, \) before they are stored or used. Applications using cloud storage backends (S3, GCS, Azure) rather than DiskService are not affected by this specific vulnerability.

Community reactions

The Rails team published a security release announcement on March 23, 2026, covering this and several other CVEs fixed in versions 7.2.3.1, 8.0.4.1, and 8.1.2.1 (Rails Blog). IBM subsequently issued advisories noting that multiple IBM products — including IBM Aspera Faspex, IBM Cloud Pak for AIOps, and IBM License Metric Tool v9 — are affected due to their use of Rails (IBM Advisory). No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability tracking.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

rails

Affected

sid

rails: 2:7.2.3.1+dfsg-1

Fixed

trixie

rails

Affected

Ubuntu

Unknown

bionic (esm-apps)

rails

Unknown

devel

rails

Unknown

focal (esm-apps)

rails

Unknown

jammy

rails

Unknown

jammy (esm-apps)

rails

Unknown

noble

rails

Unknown

noble (esm-apps)

rails

Unknown

resolute

rails

Unknown

Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management