Activerecord tenanted: ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Active Record Tenanted versions prior to 0.7.0 contain a vulnerability in the override of Active Storage's DiskService#path_for method. This vulnerability allows path traversal by not validating that the resolved filesystem path remains within the storage root directory. If an attacker can supply a blob key with path traversal sequences, they could potentially read, write, or delete arbitrary files on the server. The issue arises when untrusted user input is used as blob keys, which are expected to be trusted strings. The vulnerability has a low severity rating and no known exploits in the wild. Upgrading to version 0.7.0 or later mitigates the issue.
AI Analysis
Technical Summary
Active Record Tenanted's override of Active Storage's DiskService#path_for method does not properly validate that the resolved filesystem path remains within the designated storage root directory. This allows a path traversal vulnerability if blob keys containing sequences like '../' are used. Since blob keys are expected to be trusted, applications that use untrusted user input as blob keys are vulnerable. This can lead to unauthorized reading, writing, or deletion of arbitrary files on the server. The vulnerability affects versions prior to 0.7.0. The issue is tracked under CWE-22 (Path Traversal).
Potential Impact
An attacker able to supply a crafted blob key with path traversal sequences could manipulate file paths to access, modify, or delete files outside the intended storage directory. This could compromise server file integrity and confidentiality. The impact is limited by the requirement that the attacker can influence blob keys and the vulnerability has low severity with no known exploits in the wild.
Mitigation Recommendations
Upgrade Active Record Tenanted to version 0.7.0 or later, where this vulnerability is fixed. As a workaround, ensure that blob keys are never derived from untrusted user input, since blob keys are expected to be trusted strings. No other specific mitigations are indicated.
Activerecord tenanted: ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Description
Active Record Tenanted versions prior to 0.7.0 contain a vulnerability in the override of Active Storage's DiskService#path_for method. This vulnerability allows path traversal by not validating that the resolved filesystem path remains within the storage root directory. If an attacker can supply a blob key with path traversal sequences, they could potentially read, write, or delete arbitrary files on the server. The issue arises when untrusted user input is used as blob keys, which are expected to be trusted strings. The vulnerability has a low severity rating and no known exploits in the wild. Upgrading to version 0.7.0 or later mitigates the issue.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Active Record Tenanted's override of Active Storage's DiskService#path_for method does not properly validate that the resolved filesystem path remains within the designated storage root directory. This allows a path traversal vulnerability if blob keys containing sequences like '../' are used. Since blob keys are expected to be trusted, applications that use untrusted user input as blob keys are vulnerable. This can lead to unauthorized reading, writing, or deletion of arbitrary files on the server. The vulnerability affects versions prior to 0.7.0. The issue is tracked under CWE-22 (Path Traversal).
Potential Impact
An attacker able to supply a crafted blob key with path traversal sequences could manipulate file paths to access, modify, or delete files outside the intended storage directory. This could compromise server file integrity and confidentiality. The impact is limited by the requirement that the attacker can influence blob keys and the vulnerability has low severity with no known exploits in the wild.
Mitigation Recommendations
Upgrade Active Record Tenanted to version 0.7.0 or later, where this vulnerability is fixed. As a workaround, ensure that blob keys are never derived from untrusted user input, since blob keys are expected to be trusted strings. No other specific mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-pmwx-rm49-xv39
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["RubyGems"]
- Database Specific Severity
- LOW
- Cvss Version
- 4.0
Threat ID: 6a6ae5499c2644c7f898850a
Added to database: 07/30/2026, 05:46:49 UTC
Last enriched: 07/30/2026, 07:18:36 UTC
Last updated: 07/31/2026, 12:28:13 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.