Vulnerability DatabaseGHSA-7x4w-cj9r-h4v9

GHSA-7x4w-cj9r-h4v9
Ruby vulnerability analysis and mitigation

Overview

A critical vulnerability (GHSA-7x4w-cj9r-h4v9) was discovered in Camaleon CMS affecting versions below 2.8.1. The vulnerability, identified in September 2024, allows for remote code execution through code injection in the MediaController class. The issue stems from insufficient path validation, potentially allowing arbitrary file deletion on the server hosting Camaleon CMS (GitHub Advisory).

Technical details

The vulnerability exists in the MediaController class where actions do not properly validate whether a given path is within permitted boundaries. The issue specifically involves the delete_file method of the CamaleonCmsLocalUploader class, where file paths are joined with the root folder without proper validation. The vulnerability has received a CVSS v4.0 score of 8.6 (High), with metrics indicating Network attack vector, Low attack complexity, and High privileges required (GitHub Advisory).

Impact

If successfully exploited, this vulnerability could lead to arbitrary file deletion on the server hosting Camaleon CMS, potentially resulting in a defective CMS or system. The vulnerability affects both system confidentiality and integrity, with high impact ratings for both aspects (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 2.8.1. The recommended remediation includes normalizing all file paths constructed from untrusted user input and implementing checks to ensure resulting paths remain inside the targeted directory. Additionally, character sequences such as '..' in untrusted input used to build paths should be prohibited (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66568CRITICAL9.3
  • RubyRuby
  • ruby-saml
NoYesDec 09, 2025
CVE-2025-66567CRITICAL9.3
  • RubyRuby
  • ruby-saml
NoYesDec 09, 2025
GHSA-4249-gjr8-jpq3HIGH8.7
  • RubyRuby
  • prosemirror_to_html
NoYesNov 13, 2025
CVE-2025-64501HIGH7.6
  • RubyRuby
  • prosemirror_to_html
NoYesNov 10, 2025
GHSA-vfpf-xmwh-8m65HIGH7.6
  • RubyRuby
  • prosemirror_to_html
NoYesNov 07, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management