Decidim core: Decidim: Private exports can be downloaded through reusable links (CVE-2026-45377)
Decidim versions prior to 0.30.9 have a vulnerability where private data exports, intended to be accessible only to the export owner, can be downloaded by anyone who obtains the reusable Active Storage blob URL. This URL is exposed via a redirect after an authenticated request and can be replayed without authentication, potentially leaking personal data through various client-side channels.
AI Analysis
Technical Summary
The Decidim application implements a private export download flow that requires user authentication to access the export wrapper URL. However, this wrapper redirects to an Active Storage blob URL that is a signed bearer link not bound to the user session. Once the export owner accesses the wrapper URL, the redirect URL can be captured and reused by anyone without authentication. This allows unauthorized access to private export files. The vulnerability arises because the signed Active Storage URL is delivered via a GET redirect and is not protected by Decidim's user-scoping controls, increasing the risk of URL leakage through browser history, logs, or other client-side exposures.
Potential Impact
Unauthorized parties who obtain the redirected Active Storage blob URL can download private personal data exports without authentication. This compromises confidentiality and may lead to exposure of sensitive user data. The vulnerability does not allow modification or deletion of data, but the confidentiality breach is significant due to the nature of personal data exports.
Mitigation Recommendations
A patch is available in Decidim version 0.30.9 and later that addresses this issue by preventing the reuse of the Active Storage blob URL without proper authentication. Users should upgrade to version 0.30.9 or later. As a workaround, disabling private download URLs can reduce exposure. Patch status is confirmed by the vendor pull request referenced in the advisory.
Decidim core: Decidim: Private exports can be downloaded through reusable links (CVE-2026-45377)
Description
Decidim versions prior to 0.30.9 have a vulnerability where private data exports, intended to be accessible only to the export owner, can be downloaded by anyone who obtains the reusable Active Storage blob URL. This URL is exposed via a redirect after an authenticated request and can be replayed without authentication, potentially leaking personal data through various client-side channels.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Decidim application implements a private export download flow that requires user authentication to access the export wrapper URL. However, this wrapper redirects to an Active Storage blob URL that is a signed bearer link not bound to the user session. Once the export owner accesses the wrapper URL, the redirect URL can be captured and reused by anyone without authentication. This allows unauthorized access to private export files. The vulnerability arises because the signed Active Storage URL is delivered via a GET redirect and is not protected by Decidim's user-scoping controls, increasing the risk of URL leakage through browser history, logs, or other client-side exposures.
Potential Impact
Unauthorized parties who obtain the redirected Active Storage blob URL can download private personal data exports without authentication. This compromises confidentiality and may lead to exposure of sensitive user data. The vulnerability does not allow modification or deletion of data, but the confidentiality breach is significant due to the nature of personal data exports.
Mitigation Recommendations
A patch is available in Decidim version 0.30.9 and later that addresses this issue by preventing the reuse of the Active Storage blob URL without proper authentication. Users should upgrade to version 0.30.9 or later. As a workaround, disabling private download URLs can reduce exposure. Patch status is confirmed by the vendor pull request referenced in the advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-767h-63j4-5226
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-45377"]
- Ecosystems
- ["RubyGems"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a55ffbf68715ace432fb8fd
Added to database: 07/14/2026, 09:22:07 UTC
Last enriched: 07/14/2026, 10:02:18 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.