CVE-2025-24293: Vulnerability in Rails activestorage
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: ``` <%= image_tag blob.variant(params[:t] => params[:v]) %> ``` Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds ----------- Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong [ImageMagick security policy](https://imagemagick.org/script/security-policy.php) deployed. Credits ------- Thank you [lio346](https://hackerone.com/lio346) for reporting this!
AI Analysis
Technical Summary
Active Storage in Rails attempts to restrict image transformation methods to a safe default list. However, three allowed methods can be exploited to bypass these restrictions, enabling command injection when arbitrary user-supplied input is accepted as transformation methods or parameters. This vulnerability specifically impacts applications using Active Storage with the image_processing gem and mini_magick as the image processor. The unsafe usage pattern involves passing untrusted parameters directly to image transformations, such as in the example <%= image_tag blob.variant(params[:t] => params[:v]) %>. The vulnerability is tracked as CVE-2025-24293 with a CVSS 4.0 score of 9.2 (critical). No official patch links are provided in the input data, and the vendor advisory from Red Hat does not explicitly mention a fix or patch status.
Potential Impact
This vulnerability allows an attacker to perform command injection on systems running vulnerable versions of Rails Active Storage when untrusted user input is used for image transformation methods or parameters. This can lead to remote code execution or other severe impacts depending on the context of the application and its privileges. The CVSS score of 9.2 indicates a critical severity with network attack vector, low attack complexity, no privileges required, and no user interaction needed.
Mitigation Recommendations
No official patch or fix is explicitly stated in the provided vendor advisory content. Users should immediately avoid accepting arbitrary user input for image transformation methods or parameters, as this is unsupported and dangerous. Strict validation of all user-supplied transformation methods and parameters must be implemented. Additionally, deploying a strong ImageMagick security policy is recommended to mitigate potential command injection risks. Monitor the vendor advisory for updates regarding official patches or fixes.
CVE-2025-24293: Vulnerability in Rails activestorage
Description
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: ``` <%= image_tag blob.variant(params[:t] => params[:v]) %> ``` Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds ----------- Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong [ImageMagick security policy](https://imagemagick.org/script/security-policy.php) deployed. Credits ------- Thank you [lio346](https://hackerone.com/lio346) for reporting this!
CVSS v4.0
Score 9.2critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Active Storage in Rails attempts to restrict image transformation methods to a safe default list. However, three allowed methods can be exploited to bypass these restrictions, enabling command injection when arbitrary user-supplied input is accepted as transformation methods or parameters. This vulnerability specifically impacts applications using Active Storage with the image_processing gem and mini_magick as the image processor. The unsafe usage pattern involves passing untrusted parameters directly to image transformations, such as in the example <%= image_tag blob.variant(params[:t] => params[:v]) %>. The vulnerability is tracked as CVE-2025-24293 with a CVSS 4.0 score of 9.2 (critical). No official patch links are provided in the input data, and the vendor advisory from Red Hat does not explicitly mention a fix or patch status.
Potential Impact
This vulnerability allows an attacker to perform command injection on systems running vulnerable versions of Rails Active Storage when untrusted user input is used for image transformation methods or parameters. This can lead to remote code execution or other severe impacts depending on the context of the application and its privileges. The CVSS score of 9.2 indicates a critical severity with network attack vector, low attack complexity, no privileges required, and no user interaction needed.
Mitigation Recommendations
No official patch or fix is explicitly stated in the provided vendor advisory content. Users should immediately avoid accepting arbitrary user input for image transformation methods or parameters, as this is unsupported and dangerous. Strict validation of all user-supplied transformation methods and parameters must be implemented. Additionally, deploying a strong ImageMagick security policy is recommended to mitigate potential command injection risks. Monitor the vendor advisory for updates regarding official patches or fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- hackerone
- Date Reserved
- 2025-01-17T01:00:07.458Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2025-24293","vendor":"Red Hat"}]
Threat ID: 697d1444ac0632022278961a
Added to database: 01/30/2026, 20:27:48 UTC
Last enriched: 07/15/2026, 08:17:49 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 329
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.