๐Ÿ” CVE Alert

CVE-2025-24293

HIGH 8.1
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: ``` <%= image_tag blob.variant(params[:t] => params[:v]) %> ``` Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds ----------- Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong [ImageMagick security policy](https://imagemagick.org/script/security-policy.php) deployed. Credits ------- Thank you [lio346](https://hackerone.com/lio346) for reporting this!

Vendor rails
Product activestorage
Published Jan 30, 2026
Last Updated Jun 30, 2026
Stay Ahead of the Next One

Get instant alerts for rails activestorage

Be the first to know when new high vulnerabilities affecting rails activestorage are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Rails / activestorage
5.2 < 5.* 7.0 < 7.1.5.2 8.0 < 7.0.2.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/advisories/GHSA-r4mg-4433-c7g3 access.redhat.com: https://access.redhat.com/security/cve/CVE-2025-24293 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2435565 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-24293.json