Skip to main content
EPSS 5.3%top 7.9%

CVE-2025-24293: Vulnerability in Rails activestorage

0
Critical
VulnerabilityCVE-2025-24293cvecve-2025-24293
Published: 01/30/2026 (01/30/2026, 20:11:15 UTC)
Source: CVE Database V5
Vendor/Project: Rails
Product: activestorage

Description

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: ``` <%= image_tag blob.variant(params[:t] => params[:v]) %> ``` Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds ----------- Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong [ImageMagick security policy](https://imagemagick.org/script/security-policy.php) deployed. Credits ------- Thank you [lio346](https://hackerone.com/lio346) for reporting this!

CVSS v4.0

Score 9.2critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

Affected versions
5.27.08.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 08:17:49 UTC

Technical Analysis

Active Storage in Rails attempts to restrict image transformation methods to a safe default list. However, three allowed methods can be exploited to bypass these restrictions, enabling command injection when arbitrary user-supplied input is accepted as transformation methods or parameters. This vulnerability specifically impacts applications using Active Storage with the image_processing gem and mini_magick as the image processor. The unsafe usage pattern involves passing untrusted parameters directly to image transformations, such as in the example <%= image_tag blob.variant(params[:t] => params[:v]) %>. The vulnerability is tracked as CVE-2025-24293 with a CVSS 4.0 score of 9.2 (critical). No official patch links are provided in the input data, and the vendor advisory from Red Hat does not explicitly mention a fix or patch status.

Potential Impact

This vulnerability allows an attacker to perform command injection on systems running vulnerable versions of Rails Active Storage when untrusted user input is used for image transformation methods or parameters. This can lead to remote code execution or other severe impacts depending on the context of the application and its privileges. The CVSS score of 9.2 indicates a critical severity with network attack vector, low attack complexity, no privileges required, and no user interaction needed.

Mitigation Recommendations

No official patch or fix is explicitly stated in the provided vendor advisory content. Users should immediately avoid accepting arbitrary user input for image transformation methods or parameters, as this is unsupported and dangerous. Strict validation of all user-supplied transformation methods and parameters must be implemented. Additionally, deploying a strong ImageMagick security policy is recommended to mitigate potential command injection risks. Monitor the vendor advisory for updates regarding official patches or fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
hackerone
Date Reserved
2025-01-17T01:00:07.458Z
Cvss Version
4.0
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2025-24293","vendor":"Red Hat"}]

Threat ID: 697d1444ac0632022278961a

Added to database: 01/30/2026, 20:27:48 UTC

Last enriched: 07/15/2026, 08:17:49 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 329

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses