Loading...
Skip to main content

CVE-2026-45377

MEDIUM

Decidim: Private exports can be downloaded through reusable links

Published July 13, 2026Updated July 13, 2026Source: osv

Summary

## Description The normal `download_your_data` flow requires the requester to be logged in as the export owner, but the resulting Active Storage blob redirect URL can be replayed without authentication by anyone who obtains it. ## Technical description This private export flow turns an authenticated, user-scoped download into a reusable bearer link because the protected Decidim endpoint redirects to the underlying Active Storage blob URL. `Decidim::DownloadYourDataController#download_file` correctly scopes the export record to `current_user`, so the wrapper route itself is not directly accessible to another user. However, once the owner performs that authenticated GET request, the response redirects to a signed Active Storage URL that is no longer bound to the user session. Anyone who learns that URL can replay it and retrieve the file without being logged in as the export owner. Because the blob redirect URL is delivered through a GET request and appears in the redirect chain, it is more likely to leak through browser history, logs, proxy tooling, screenshots, copied links, support transcripts, or other client-side handling of URLs. Reproduction steps: Step 1. Generate or locate a completed export in the Web UI. 1. Sign in as `user@example.org` at `http://localhost:3001/users/sign_in`. 2. Open `http://localhost:3001/download_your_data`. 3. Request a new export from the page and wait until the export becomes downloadable. 4. Open the completed export entry from the list and copy its wrapper URL, for example `http://localhost:3001/download_your_data/download?uuid=07286e61-932d-46d4-bd74-bcd1340c503f `. Step 2. Download through the authenticated wrapper route. 1. While still signed in as user@example.org, open the wrapper URL in the browser. 2. Confirm that this Decidim route requires the owner session and is not directly usable when logged out or when logged in as another user. Step 3. Capture the final bearer URL in the redirect chain. 1. In DevTools Network or Burp, inspect the redirect sequence for the wrapper request. 2. Copy the Active Storage redirect URL, typically matching `http://localhost:3001/rails/active_storage/blobs/redirect/<SIGNED_ID>/<FILENAME>`. 3. Note that the Active Storage redirect URL is no longer protected by the Decidim ownership check. Step 4. Replay the final file URL without authentication. 1. Open a private window or separate browser with no Decidim session. 2. Paste the copied `http://localhost:3001/rails/active_storage/blobs/redirect/<SIGNED_ID>/<FILENAME>` URL. 3. Confirm the export file still downloads even though you are not logged in as the export owner. ### Impact Personal data exports can be retrieved through leakage channels such as browser history, logs, referrers, screenshots, copied links, support transcripts, intercepted email content, or other client-side disclosure of the GET URL. ### Patches See https://github.com/decidim/decidim/pull/16680 ### Workarounds Disable Private Downloads URLs ### Reference OWASP A01:2021 Broken Access Control ### Credits This issue was discovered in a security audit organized by the [Decidim Association](https://decidim.org) and made by [Radically Open Security](https://www.radicallyopensecurity.com/) against Decidim financed by [NGI](https://ngi.eu/).

Remediation

Upgrade to the fixed version using your package manager.

Bundler
Update decidim-core to 0.31.5 or later
gem install decidim-core -v 0.31.5
Bundler
Update decidim-core to 0.32.0 or later
gem install decidim-core -v 0.32.0
Bundler
Update decidim-core to 0.30.9 or later
gem install decidim-core -v 0.30.9

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (3)

PackageEcosystemAffectedFixed In
decidim-core
rubygems
0.31.0, 0.31.0.rc1, 0.31.0.rc2, 0.31.1 (+3 more)0.31.5
decidim-core
rubygems
0.32.0.rc1, 0.32.0.rc2, 0.32.0.rc30.32.0
decidim-core
rubygems
0.0.1, 0.0.1.alpha1, 0.0.1.alpha2, 0.0.1.alpha3 (+158 more)0.30.9

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

  • CWE-200
    Information ExposureMITRE

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 6.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Frequently Asked Questions

What is CVE-2026-45377?
Decidim: Private exports can be downloaded through reusable links This vulnerability has been assigned a severity rating of MEDIUM (CVSS score: 6.5/10).
How do I check if my project is affected by CVE-2026-45377?
CVE-2026-45377 affects decidim-core. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-45377 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
6.5

Exploitation requires specific conditions or has limited impact. Remediate within weeks.

Also Known As

GHSA-767h-63j4-5226

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies