Vulnerable Library - rails-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/actionview-5.2.2.gem
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Exploit Maturity |
EPSS |
Dependency |
Type |
Fixed in (rails version) |
Remediation Possible** |
Reachability |
| CVE-2026-66066 |
Critical |
10.0 |
Functional |
27.861% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-30123 |
Critical |
10.0 |
Not Defined |
1.801% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-71407 |
Critical |
9.8 |
Not Defined |
0.418% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-24293 |
Critical |
9.8 |
Functional |
5.082% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-58378 |
Critical |
9.8 |
Not Defined |
0.342% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-51000 |
Critical |
9.8 |
Not Defined |
0.441% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-32224 |
Critical |
9.8 |
Not Defined |
2.386% |
activerecord-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-21831 |
Critical |
9.8 |
Not Defined |
3.025% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8165 |
Critical |
9.8 |
Not Defined |
45.732% |
activesupport-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-5420 |
Critical |
9.8 |
Functional |
92.144% |
railties-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33195 |
Critical |
9.1 |
Not Defined |
0.567% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| WS-2022-0089 |
High |
8.8 |
Not Defined |
|
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-22794 |
High |
8.8 |
Not Defined |
2.153% |
activerecord-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-3518 |
High |
8.8 |
Not Defined |
3.653% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-30560 |
High |
8.8 |
Not Defined |
21.458% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-61666 |
High |
8.6 |
Not Defined |
0.338% |
websocket-driver-0.7.0.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-50999 |
High |
8.6 |
Not Defined |
0.301% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-3517 |
High |
8.6 |
Not Defined |
8.28% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-29181 |
High |
8.2 |
Not Defined |
3.23% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23634 |
High |
8.0 |
Not Defined |
2.107% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-71406 |
High |
7.8 |
Not Defined |
0.187% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| WS-2023-0224 |
High |
7.5 |
Not Defined |
|
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-79770 |
High |
7.5 |
Not Defined |
0.278% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54904 |
High |
7.5 |
Not Defined |
0.673% |
concurrent-ruby-1.1.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34829 |
High |
7.5 |
Not Defined |
0.369% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34785 |
High |
7.5 |
Not Defined |
0.387% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33202 |
High |
7.5 |
Not Defined |
0.646% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33176 |
High |
7.5 |
Not Defined |
0.61% |
activesupport-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33174 |
High |
7.5 |
Not Defined |
0.61% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-22860 |
High |
7.5 |
Not Defined |
0.665% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61919 |
High |
7.5 |
Not Defined |
0.605% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61772 |
High |
7.5 |
Not Defined |
0.868% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61771 |
High |
7.5 |
Not Defined |
0.523% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61770 |
High |
7.5 |
Not Defined |
0.868% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-59830 |
High |
7.5 |
Not Defined |
0.573% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-46727 |
High |
7.5 |
Not Defined |
1.157% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-27610 |
High |
7.5 |
Not Defined |
1.131% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-47889 |
High |
7.5 |
Not Defined |
0.937% |
actionmailer-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-47887 |
High |
7.5 |
Not Defined |
1.041% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-41128 |
High |
7.5 |
Not Defined |
1.095% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-34459 |
High |
7.5 |
Not Defined |
2.298% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-54354 |
High |
7.5 |
Not Defined |
0.35% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-27530 |
High |
7.5 |
Not Defined |
1.83% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-22799 |
High |
7.5 |
Not Defined |
1.049% |
globalid-0.4.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-22796 |
High |
7.5 |
Not Defined |
1.712% |
activesupport-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-22795 |
High |
7.5 |
Not Defined |
2.278% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-22792 |
High |
7.5 |
Not Defined |
1.695% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-50998 |
High |
7.5 |
Not Defined |
0.35% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-44572 |
High |
7.5 |
Not Defined |
1.617% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-44571 |
High |
7.5 |
Not Defined |
1.503% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-44570 |
High |
7.5 |
Not Defined |
1.626% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-44566 |
High |
7.5 |
Not Defined |
1.265% |
activerecord-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-31163 |
High |
7.5 |
Not Defined |
2.23% |
tzinfo-1.2.5.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-30122 |
High |
7.5 |
Not Defined |
2.056% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-24836 |
High |
7.5 |
Not Defined |
3.519% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23517 |
High |
7.5 |
Not Defined |
1.454% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23516 |
High |
7.5 |
Not Defined |
1.095% |
loofah-2.4.0.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23514 |
High |
7.5 |
Not Defined |
1.686% |
loofah-2.4.0.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-47996 |
High |
7.5 |
Not Defined |
0.515% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-41098 |
High |
7.5 |
Not Defined |
1.447% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-22904 |
High |
7.5 |
Not Defined |
4.808% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-22885 |
High |
7.5 |
Not Defined |
4.195% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-22880 |
High |
7.5 |
Not Defined |
4.434% |
activerecord-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8164 |
High |
7.5 |
Not Defined |
4.198% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8162 |
High |
7.5 |
Not Defined |
3.028% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-5419 |
High |
7.5 |
Not Defined |
8.671% |
actionview-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2019-5418 |
High |
7.5 |
High |
98.507% |
actionview-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2018-25032 |
High |
7.5 |
Not Defined |
51.733% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23633 |
High |
7.4 |
Not Defined |
2.226% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23519 |
High |
7.2 |
Not Defined |
0.988% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57235 |
Medium |
6.5 |
Not Defined |
0.426% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33658 |
Medium |
6.5 |
Not Defined |
0.434% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-25184 |
Medium |
6.5 |
Not Defined |
1.162% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8167 |
Medium |
6.5 |
Not Defined |
1.485% |
actionview-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-23913 |
Medium |
6.3 |
Not Defined |
0.643% |
detected in multiple dependencies |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57438 |
Medium |
6.2 |
Not Defined |
0.125% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-73648 |
Medium |
6.1 |
Not Defined |
0.396% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-54133 |
Medium |
6.1 |
Not Defined |
1.009% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53989 |
Medium |
6.1 |
Not Defined |
0.463% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53988 |
Medium |
6.1 |
Not Defined |
0.435% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53987 |
Medium |
6.1 |
Not Defined |
0.435% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53986 |
Medium |
6.1 |
Not Defined |
0.462% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-53985 |
Medium |
6.1 |
Not Defined |
0.581% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-32209 |
Medium |
6.1 |
Not Defined |
29.353% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-27777 |
Medium |
6.1 |
Not Defined |
1.639% |
actionview-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23520 |
Medium |
6.1 |
Not Defined |
1.11% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23518 |
Medium |
6.1 |
Not Defined |
0.867% |
rails-html-sanitizer-1.0.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-23515 |
Medium |
6.1 |
Not Defined |
0.792% |
loofah-2.4.0.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2022-22577 |
Medium |
6.1 |
Not Defined |
1.759% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34830 |
Medium |
5.9 |
Not Defined |
0.209% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2021-3537 |
Medium |
5.9 |
Not Defined |
3.503% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54465 |
Medium |
5.8 |
Not Defined |
0.344% |
websocket-driver-0.7.0.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54464 |
Medium |
5.8 |
Not Defined |
0.445% |
websocket-driver-0.7.0.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54463 |
Medium |
5.8 |
Not Defined |
0.344% |
websocket-driver-0.7.0.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-61780 |
Medium |
5.8 |
Not Defined |
0.434% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-55193 |
Medium |
5.8 |
Not Defined |
0.565% |
activerecord-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-26141 |
Medium |
5.8 |
Not Defined |
1.612% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-79769 |
Medium |
5.5 |
Not Defined |
0.181% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-58377 |
Medium |
5.5 |
Not Defined |
0.193% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-38037 |
Medium |
5.5 |
Not Defined |
0.274% |
activesupport-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33168 |
Medium |
5.4 |
Not Defined |
0.713% |
actionview-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-25500 |
Medium |
5.4 |
Not Defined |
0.224% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-15169 |
Medium |
5.4 |
Not Defined |
2.372% |
actionview-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-79772 |
Medium |
5.3 |
Not Defined |
0.262% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-79771 |
Medium |
5.3 |
Not Defined |
0.304% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57437 |
Medium |
5.3 |
Not Defined |
0.402% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57436 |
Medium |
5.3 |
Not Defined |
0.402% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57435 |
Medium |
5.3 |
Not Defined |
0.46% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57434 |
Medium |
5.3 |
Not Defined |
0.46% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57236 |
Medium |
5.3 |
Not Defined |
0.341% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54905 |
Medium |
5.3 |
Not Defined |
0.153% |
concurrent-ruby-1.1.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34826 |
Medium |
5.3 |
Not Defined |
0.38% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34786 |
Medium |
5.3 |
Not Defined |
0.195% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34763 |
Medium |
5.3 |
Not Defined |
0.24% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34230 |
Medium |
5.3 |
Not Defined |
0.43% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33169 |
Medium |
5.3 |
Not Defined |
0.498% |
activesupport-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-27111 |
Medium |
5.3 |
Not Defined |
0.729% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-26146 |
Medium |
5.3 |
Not Defined |
1.996% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2024-26144 |
Medium |
5.3 |
Not Defined |
1.129% |
detected in multiple dependencies |
Transitive |
N/A* |
❌ |
|
| CVE-2024-25126 |
Medium |
5.3 |
Not Defined |
35.376% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-28120 |
Medium |
5.3 |
Not Defined |
0.923% |
activesupport-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-27539 |
Medium |
5.3 |
Not Defined |
1.081% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-34831 |
Medium |
4.8 |
Not Defined |
0.147% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-73490 |
Medium |
4.7 |
Not Defined |
0.18% |
loofah-2.4.0.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33173 |
Medium |
4.3 |
Not Defined |
0.39% |
activestorage-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-33170 |
Medium |
4.3 |
Not Defined |
0.327% |
activesupport-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-8166 |
Medium |
4.3 |
Not Defined |
1.673% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-32441 |
Medium |
4.2 |
Not Defined |
0.229% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-54906 |
Medium |
4.0 |
Not Defined |
0.252% |
concurrent-ruby-1.1.4.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2023-28362 |
Medium |
4.0 |
Not Defined |
0.332% |
actionpack-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-5267 |
Medium |
4.0 |
Not Defined |
1.525% |
actionview-5.2.2.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-26961 |
Low |
3.7 |
Not Defined |
0.253% |
rack-2.2.3.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-6490 |
Low |
3.3 |
Proof of concept |
0.16% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2025-71346 |
Low |
2.9 |
Not Defined |
0.18% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2026-57234 |
Low |
2.6 |
Not Defined |
0.198% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
| CVE-2020-26247 |
Low |
2.6 |
Not Defined |
1.077% |
nokogiri-1.10.9.gem |
Transitive |
N/A* |
❌ |
|
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Partial details (10 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.
CVE-2026-66066
Vulnerable Library - activestorage-5.2.2.gem
Attach cloud and local files in Rails applications.
Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- ❌ activestorage-5.2.2.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
Publish Date: 2026-07-30
URL: CVE-2026-66066
Threat Assessment
Exploit Maturity: Functional
EPSS: 27.861%
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-07-30
Fix Resolution: activestorage - 8.1.3.1,activestorage - 8.0.5.1,activestorage - 7.2.3.2,https://github.com/rails/rails.git - v8.0.5.1,https://github.com/rails/rails.git - v7.2.3.2,https://github.com/rails/rails.git - v8.1.3.1
CVE-2022-30123
Vulnerable Library - rack-2.2.3.gem
Rack provides a minimal, modular and adaptable interface for developing
web applications in Ruby. By wrapping HTTP requests and responses in
the simplest way possible, it unifies and distills the API for web
servers, web frameworks, and software in between (the so-called
middleware) into a single method call.
Library home page: https://rubygems.org/gems/rack-2.2.3.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/rack-2.2.3.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- railties-5.2.2.gem
- actionpack-5.2.2.gem
- ❌ rack-2.2.3.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
Publish Date: 2022-12-05
URL: CVE-2022-30123
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 1.801%
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-wq4h-7r42-5hrr
Release Date: 2022-12-05
Fix Resolution: rack - 2.0.9.1,2.1.4.1,2.2.3.1
CVE-2025-71407
Vulnerable Library - nokogiri-1.10.9.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- railties-5.2.2.gem
- actionpack-5.2.2.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.10.9.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.
Publish Date: 2026-08-25
URL: CVE-2025-71407
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.418%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.18.3,https://github.com/sparklemotion/nokogiri.git - v1.18.3
CVE-2025-24293
Vulnerable Library - activestorage-5.2.2.gem
Attach cloud and local files in Rails applications.
Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- ❌ activestorage-5.2.2.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: "<%= image_tag blob.variant(params[:t] => params[:v]) %>" Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds ----------- Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong "ImageMagick security policy" (https://imagemagick.org/script/security-policy.php) deployed. Credits ------- Thank you "lio346" (https://hackerone.com/lio346) for reporting this!
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026-01-30
URL: CVE-2025-24293
Threat Assessment
Exploit Maturity: Functional
EPSS: 5.082%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-r4mg-4433-c7g3
Release Date: 2026-01-30
Fix Resolution: https://github.com/rails/rails.git - v8.0.2.1,https://github.com/rails/rails.git - v7.2.2.2,https://github.com/rails/rails.git - v7.1.5.2
CVE-2024-58378
Vulnerable Library - nokogiri-1.10.9.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- railties-5.2.2.gem
- actionpack-5.2.2.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.10.9.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
Publish Date: 2026-08-25
URL: CVE-2024-58378
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.342%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-xc9x-jj77-9p9j
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.15.6,nokogiri - 1.16.2,https://github.com/sparklemotion/nokogiri.git - v1.15.6,https://github.com/sparklemotion/nokogiri.git - v1.16.2
CVE-2022-51000
Vulnerable Library - nokogiri-1.10.9.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among
Nokogiri's many features is the ability to search documents via XPath
or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- railties-5.2.2.gem
- actionpack-5.2.2.gem
- rails-dom-testing-2.0.3.gem
- ❌ nokogiri-1.10.9.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheets is vulnerable to a denial-of-service attack. Via CVE-2022-23308 in libxml2, an application parsing an untrusted document with parse option DTDVALID set to true and NOENT set to false may be vulnerable to denial of service, memory disclosure, or code execution. Nokogiri 1.13.2 upgrades vendored libxml2 to 2.9.13 and libxslt to 1.1.35.
Publish Date: 2026-08-25
URL: CVE-2022-51000
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.441%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.13.2,https://github.com/sparklemotion/nokogiri.git - v1.13.2
CVE-2022-32224
Vulnerable Library - activerecord-5.2.2.gem
Databases on Rails. Build a persistent domain model by mapping database tables to Ruby classes. Strong conventions for associations, validations, aggregations, migrations, and testing come baked-in.
Library home page: https://rubygems.org/gems/activerecord-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activerecord-5.2.2.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- ❌ activerecord-5.2.2.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.
Publish Date: 2022-12-05
URL: CVE-2022-32224
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 2.386%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-3hhc-qp5v-9p2j
Release Date: 2022-12-05
Fix Resolution: activerecord - 7.0.3.1,activerecord - 6.0.5.1,activerecord - 5.2.8.1,activerecord - 6.1.6.1
CVE-2022-21831
Vulnerable Library - activestorage-5.2.2.gem
Attach cloud and local files in Rails applications.
Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- ❌ activestorage-5.2.2.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
Publish Date: 2022-05-26
URL: CVE-2022-21831
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 3.025%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-w749-p3v6-hccq
Release Date: 2022-05-26
Fix Resolution: activestorage - 6.1.4.7,activestorage - 5.2.6.3,activestorage - 7.0.2.3,activestorage - 6.0.4.7
CVE-2020-8165
Vulnerable Library - activesupport-5.2.2.gem
A toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Rich support for multibyte strings, internationalization, time zones, and testing.
Library home page: https://rubygems.org/gems/activesupport-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activesupport-5.2.2.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- ❌ activesupport-5.2.2.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
Publish Date: 2020-06-19
URL: CVE-2020-8165
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 45.732%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-2p68-f74v-9wc6
Release Date: 2020-06-19
Fix Resolution: activesupport - 5.2.4.3,activesupport - 6.0.3.1
CVE-2019-5420
Vulnerable Library - railties-5.2.2.gem
Rails internals: application bootup, plugins, generators, and rake tasks.
Library home page: https://rubygems.org/gems/railties-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/railties-5.2.2.gem
Dependency Hierarchy:
- rails-5.2.2.gem (Root Library)
- ❌ railties-5.2.2.gem (Vulnerable Library)
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
Publish Date: 2019-03-27
URL: CVE-2019-5420
Threat Assessment
Exploit Maturity: Functional
EPSS: 92.144%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-m42h-mh85-4qgc
Release Date: 2019-03-27
Fix Resolution: railties - 5.2.2.1
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/actionview-5.2.2.gem
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - activestorage-5.2.2.gem
Attach cloud and local files in Rails applications.
Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
Publish Date: 2026-07-30
URL: CVE-2026-66066
Threat Assessment
Exploit Maturity: Functional
EPSS: 27.861%
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-07-30
Fix Resolution: activestorage - 8.1.3.1,activestorage - 8.0.5.1,activestorage - 7.2.3.2,https://github.com/rails/rails.git - v8.0.5.1,https://github.com/rails/rails.git - v7.2.3.2,https://github.com/rails/rails.git - v8.1.3.1
Vulnerable Library - rack-2.2.3.gem
Rack provides a minimal, modular and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers, web frameworks, and software in between (the so-called middleware) into a single method call.
Library home page: https://rubygems.org/gems/rack-2.2.3.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/rack-2.2.3.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
Publish Date: 2022-12-05
URL: CVE-2022-30123
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 1.801%
CVSS 3 Score Details (10.0)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-wq4h-7r42-5hrr
Release Date: 2022-12-05
Fix Resolution: rack - 2.0.9.1,2.1.4.1,2.2.3.1
Vulnerable Library - nokogiri-1.10.9.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during validation against untrusted XML Schemas. Attackers can trigger these vulnerabilities by providing malicious DTD content or untrusted XSD files to cause denial of service or potential code execution.
Publish Date: 2026-08-25
URL: CVE-2025-71407
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.418%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.18.3,https://github.com/sparklemotion/nokogiri.git - v1.18.3
Vulnerable Library - activestorage-5.2.2.gem
Attach cloud and local files in Rails applications.
Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: "<%= image_tag blob.variant(params[:t] => params[:v]) %>" Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds ----------- Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong "ImageMagick security policy" (https://imagemagick.org/script/security-policy.php) deployed. Credits ------- Thank you "lio346" (https://hackerone.com/lio346) for reporting this!
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: 2026-01-30
URL: CVE-2025-24293
Threat Assessment
Exploit Maturity: Functional
EPSS: 5.082%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-r4mg-4433-c7g3
Release Date: 2026-01-30
Fix Resolution: https://github.com/rails/rails.git - v8.0.2.1,https://github.com/rails/rails.git - v7.2.2.2,https://github.com/rails/rails.git - v7.1.5.2
Vulnerable Library - nokogiri-1.10.9.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
Publish Date: 2026-08-25
URL: CVE-2024-58378
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.342%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-xc9x-jj77-9p9j
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.15.6,nokogiri - 1.16.2,https://github.com/sparklemotion/nokogiri.git - v1.15.6,https://github.com/sparklemotion/nokogiri.git - v1.16.2
Vulnerable Library - nokogiri-1.10.9.gem
Nokogiri (鋸) is an HTML, XML, SAX, and Reader parser. Among Nokogiri's many features is the ability to search documents via XPath or CSS3 selectors.
Library home page: https://rubygems.org/gems/nokogiri-1.10.9.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/nokogiri-1.10.9.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML with untrusted XSL stylesheets is vulnerable to a denial-of-service attack. Via CVE-2022-23308 in libxml2, an application parsing an untrusted document with parse option DTDVALID set to true and NOENT set to false may be vulnerable to denial of service, memory disclosure, or code execution. Nokogiri 1.13.2 upgrades vendored libxml2 to 2.9.13 and libxslt to 1.1.35.
Publish Date: 2026-08-25
URL: CVE-2022-51000
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.441%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-25
Fix Resolution: nokogiri - 1.13.2,https://github.com/sparklemotion/nokogiri.git - v1.13.2
Vulnerable Library - activerecord-5.2.2.gem
Databases on Rails. Build a persistent domain model by mapping database tables to Ruby classes. Strong conventions for associations, validations, aggregations, migrations, and testing come baked-in.
Library home page: https://rubygems.org/gems/activerecord-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activerecord-5.2.2.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.
Publish Date: 2022-12-05
URL: CVE-2022-32224
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 2.386%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-3hhc-qp5v-9p2j
Release Date: 2022-12-05
Fix Resolution: activerecord - 7.0.3.1,activerecord - 6.0.5.1,activerecord - 5.2.8.1,activerecord - 6.1.6.1
Vulnerable Library - activestorage-5.2.2.gem
Attach cloud and local files in Rails applications.
Library home page: https://rubygems.org/gems/activestorage-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activestorage-5.2.2.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
Publish Date: 2022-05-26
URL: CVE-2022-21831
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 3.025%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-w749-p3v6-hccq
Release Date: 2022-05-26
Fix Resolution: activestorage - 6.1.4.7,activestorage - 5.2.6.3,activestorage - 7.0.2.3,activestorage - 6.0.4.7
Vulnerable Library - activesupport-5.2.2.gem
A toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Rich support for multibyte strings, internationalization, time zones, and testing.
Library home page: https://rubygems.org/gems/activesupport-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/activesupport-5.2.2.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
Publish Date: 2020-06-19
URL: CVE-2020-8165
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 45.732%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-2p68-f74v-9wc6
Release Date: 2020-06-19
Fix Resolution: activesupport - 5.2.4.3,activesupport - 6.0.3.1
Vulnerable Library - railties-5.2.2.gem
Rails internals: application bootup, plugins, generators, and rake tasks.
Library home page: https://rubygems.org/gems/railties-5.2.2.gem
Sample Path to Dependency File: /Gemfile.lock
Path to vulnerable library: /tmp/containerbase/cache/.ruby/cache/railties-5.2.2.gem
Dependency Hierarchy:
Found in HEAD commit: ae67ae136f4f5bfdcb7f4ca6fce2192ea18513b7
Found in base branch: main
Vulnerability Details
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
Publish Date: 2019-03-27
URL: CVE-2019-5420
Threat Assessment
Exploit Maturity: Functional
EPSS: 92.144%
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-m42h-mh85-4qgc
Release Date: 2019-03-27
Fix Resolution: railties - 5.2.2.1