CVE-2025-24293
published 2026-01-30CVE-2025-24293: # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation…
PriorityP357high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.39%
82.1th percentile
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: ``` params[:v]) %> ``` Where the transformation method or its arguments are untrusted arbitrary input. All users running an affected release should either upgrade or use one of the workarounds immediately. Workarounds Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous. Strict validation of user supplied methods and parameters should be performed as well as having a strong [ImageMagick security policy](https://imagemagick.org/script/security-policy.php) deployed. Credits Thank you [lio346](https://hackerone.com/lio346) for reporting this!
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2:6.1.7.10+dfsg-1~deb12u2 (bookworm) | rails 2:6.1.7.10+dfsg-1~deb12u2 (bookworm) |
| rails | activestorage | >= 5.2 < 5.* | 5.* |
| rails | activestorage | >= 5.2.0 < 7.1.5.2 | 7.1.5.2 |
| rails | activestorage | >= 7.0 < 7.1.5.2 | 7.1.5.2 |
| rails | activestorage | >= 7.2 < 7.2.2.2 | 7.2.2.2 |
| rails | activestorage | >= 8.0 < 7.0.2.1 | 7.0.2.1 |
| rails | activestorage | >= 8.0 < 8.0.2.1 | 8.0.2.1 |
| rubyonrails | rails | >= 0 < 2:6.0.3.7+dfsg-2+deb11u4 | 2:6.0.3.7+dfsg-2+deb11u4 |
| rubyonrails | rails | >= 0 < 2:6.1.7.10+dfsg-1~deb12u2 | 2:6.1.7.10+dfsg-1~deb12u2 |
| rubyonrails | rails | >= 0 < 2:7.2.2.2+dfsg-2~deb13u1 | 2:7.2.2.2+dfsg-2~deb13u1 |
| rubyonrails | rails | >= 0 < 2:7.2.2.2+dfsg-1 | 2:7.2.2.2+dfsg-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect Rails Active Storage image transformation requests where user-supplied input is passed directly as transformation methods or parameters (e.g., via params[:v]) to image_processing with mini_magick backend — flag requests where transformation arguments contain shell metacharacters or command sequences ↗
- →This vulnerability is only exploitable when Active Storage is used together with the image_processing gem AND mini_magick as the image processor — scope detection to applications meeting both conditions ↗
- ·Exploitation is NOT possible in default Active Storage configurations — the vulnerable condition requires application code to explicitly pass untrusted user input as image transformation methods or parameters ↗
- ·Consuming user-supplied input for image transformation methods or their parameters is explicitly unsupported and dangerous behavior in Active Storage ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa9.2CRITICAL
osv9.2CRITICAL
vendor_debian9.2CRITICAL
vendor_redhat9.2CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
activestorage: Code injection in Active Storage when used in conjunction with the image_processing gem
vendor_redhat·2026-01-30·CVSS 9.2
CVE-2025-24293 [CRITICAL] CWE-88 activestorage: Code injection in Active Storage when used in conjunction with the image_processing gem
activestorage: Code injection in Active Storage when used in conjunction with the image_processing gem
# Active Storage allowed transformation methods potentially unsafe
Active Storage attempts to prevent the use of potentially unsafe image
transformation methods and parameters by default.
The default allowed list contains three methods allow for the circumvention
of the safe defaults which enables potential command injection
vulnerabilities in cases where arbitrary user supplied input is accepted as
valid transformation methods or parameters.
Impact
This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor.
Vulnerable code will look something similar to this:
```
params[:v]) %>
```
Where the
Debian
CVE-2025-24293: rails - # Active Storage allowed transformation methods potentially unsafe
Active Sto...
vendor_debian·2025·CVSS 9.2
CVE-2025-24293 [CRITICAL] CVE-2025-24293: rails - # Active Storage allowed transformation methods potentially unsafe
Active Sto...
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: ``` params[:v]) %> ``` Where the transformation method or its arguments are untrusted arbitrary input. All users running an affect
VulDB
activestorage Gem on Ruby command injection (EUVD-2025-29509 / Nessus ID 269912)
vuldb·2026-07-01·CVSS 8.1
CVE-2025-24293 [HIGH] activestorage Gem on Ruby command injection (EUVD-2025-29509 / Nessus ID 269912)
A vulnerability labeled as critical has been found in activestorage Gem on Ruby. Affected by this vulnerability is an unknown functionality. Such manipulation leads to command injection.
This vulnerability is listed as CVE-2025-24293. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
OSV
CVE-2025-24293: # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformati
osv·2026-01-30·CVSS 9.2
CVE-2025-24293 [CRITICAL] CVE-2025-24293: # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformati
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters. Impact ------ This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor. Vulnerable code will look something similar to this: ``` params[:v]) %> ``` Where the transformation method or its arguments are untrusted arbitrary input. All users running an affect
GHSA
Active Storage allowed transformation methods that were potentially unsafe
ghsa·2025-08-14·CVSS 9.2
CVE-2025-24293 [CRITICAL] CWE-77 Active Storage allowed transformation methods that were potentially unsafe
Active Storage allowed transformation methods that were potentially unsafe
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default.
The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters.
This has been assigned the CVE identifier CVE-2025-24293.
Versions Affected: >= 5.2.0
Not affected: params[:v]) %>
```
Where the transformation method or its arguments are untrusted arbitrary input.
All users running an affected release should either upgrade or use one of the workarounds immediately.
Releases
The fixed releases are
OSV
Active Storage allowed transformation methods that were potentially unsafe
osv·2025-08-14·CVSS 9.2
CVE-2025-24293 [CRITICAL] Active Storage allowed transformation methods that were potentially unsafe
Active Storage allowed transformation methods that were potentially unsafe
Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default.
The default allowed list contains three methods allowing for the circumvention of the safe defaults which enables potential command injection vulnerabilities in cases where arbitrary user supplied input is accepted as valid transformation methods or parameters.
This has been assigned the CVE identifier CVE-2025-24293.
Versions Affected: >= 5.2.0
Not affected: params[:v]) %>
```
Where the transformation method or its arguments are untrusted arbitrary input.
All users running an affected release should either upgrade or use one of the workarounds immediately.
Releases
The fixed releases are
No detection rules found.
No public exploits indexed.
2026-01-30
Published