activestorage Security Analysis
activestorage has 11 known security vulnerabilities in RubyGems (Ruby). Upgrade to version 8.1.3.1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 8.1.3.1
Upgrading to 8.1.3.1 or later resolves all 11 known vulnerabilities in activestorage. Run: gem install activestorage -v 8.1.3.1
Is activestorage in your project?
Check if you're affected and upgrade to 8.1.3.1 to stay secure.
Vulnerabilities
11 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-66066 Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing | CRITICAL | 0.1, 5.2.0, 5.2.0.beta1, 5.2.0.beta2 (+177 more) | 7.2.3.2, 8.0.5.1, 8.1.3.1 |
| CVE-2025-24293 Active Storage allowed transformation methods that were potentially unsafe | CRITICAL | 8.0.0, 8.0.0.1, 8.0.1, 8.0.2 (+148 more) | 8.0.2.1, 7.2.2.2, 7.1.5.2 |
| CVE-2022-21831 Possible code injection vulnerability in Rails / Active Storage | CRITICAL | 5.2.0, 5.2.1, 5.2.1.1, 5.2.1.rc1 (+60 more) | 5.2.6.3, 6.0.4.7, 6.1.4.7 (+1 more) |
| CVE-2026-33195 Rails Active Storage has possible Path Traversal in DiskService | HIGH | 8.1.0, 8.1.0.beta1, 8.1.0.rc1, 8.1.1 (+172 more) | 8.1.2.1, 8.0.4.1, 7.2.3.1 |
| CVE-2020-8162 Circumvention of file size limits in ActiveStorage | HIGH | 5.2.0, 5.2.0.beta1, 5.2.0.beta2, 5.2.0.rc1 (+23 more) | 5.2.4.3, 6.0.3.1 |
| CVE-2026-33202 Rails Active Storage has possible glob injection in its DiskService | MEDIUM | 8.1.0, 8.1.0.beta1, 8.1.0.rc1, 8.1.1 (+172 more) | 8.1.2.1, 8.0.4.1, 7.2.3.1 |
| CVE-2026-33174 Rails Active Storage has a possible DoS vulnerability when in proxy mode via Range requests | MEDIUM | 8.1.0, 8.1.0.beta1, 8.1.0.rc1, 8.1.1 (+172 more) | 8.1.2.1, 8.0.4.1, 7.2.3.1 |
| CVE-2026-33173 Rails Active Storage has possible content type bypass via metadata in direct uploads | MEDIUM | 8.1.0, 8.1.0.beta1, 8.1.0.rc1, 8.1.1 (+172 more) | 8.1.2.1, 8.0.4.1, 7.2.3.1 |
| CVE-2024-26144 Rails has possible Sensitive Session Information Leak in Active Storage | MEDIUM | 5.2.0, 5.2.1, 5.2.1.1, 5.2.1.rc1 (+105 more) | 6.1.7.7, 7.0.8.1 |
| CVE-2018-16477 Exposure of Sensitive Information to an Unauthorized Actor in activestorage | MEDIUM | 5.2.0, 5.2.1, 5.2.1.rc1 | 5.2.1.1 |
| CVE-2026-33658 Rails Active Storage has a possible DoS vulnerability in proxy mode via multi-range requests | LOW | 8.1.0, 8.1.1, 8.1.2, 8.0.0 (+167 more) | 8.1.2.1, 8.0.4.1, 7.2.3.1 |
About This Data
Vulnerability data for activestorage is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related RubyGems (Ruby) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of activestorage.