cbcvebase.
CVE-2025-24293
published 2026-01-30

CVE-2025-24293: # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation…

PriorityP357high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.39%
82.1th percentile
# Active Storage allowed transformation methods potentially unsafe

Active Storage attempts to prevent the use of potentially unsafe image
transformation methods and parameters by default.

The default allowed list contains three methods allow for the circumvention
of the safe defaults which enables potential command injection
vulnerabilities in cases where arbitrary user supplied input is accepted as
valid transformation methods or parameters.


Impact
This vulnerability impacts applications that use Active Storage with the image_processing processing gem in addition to mini_magick as the image processor.

Vulnerable code will look something similar to this:
```
params[:v]) %>
```

Where the transformation method or its arguments are untrusted arbitrary input.

All users running an affected release should either upgrade or use one of the workarounds immediately.



Workarounds
Consuming user supplied input for image transformation methods or their parameters is unsupported behavior and should be considered dangerous.

Strict validation of user supplied methods and parameters should be performed
as well as having a strong [ImageMagick security
policy](https://imagemagick.org/script/security-policy.php) deployed.

Credits

Thank you [lio346](https://hackerone.com/lio346) for reporting this!

Affected

11 ranges
VendorProductVersion rangeFixed in
debianrails< rails 2:6.1.7.10+dfsg-1~deb12u2 (bookworm)rails 2:6.1.7.10+dfsg-1~deb12u2 (bookworm)
railsactivestorage>= 5.2 < 5.*5.*
railsactivestorage>= 5.2.0 < 7.1.5.27.1.5.2
railsactivestorage>= 7.0 < 7.1.5.27.1.5.2
railsactivestorage>= 7.2 < 7.2.2.27.2.2.2
railsactivestorage>= 8.0 < 7.0.2.17.0.2.1
railsactivestorage>= 8.0 < 8.0.2.18.0.2.1
rubyonrailsrails>= 0 < 2:6.0.3.7+dfsg-2+deb11u42:6.0.3.7+dfsg-2+deb11u4
rubyonrailsrails>= 0 < 2:6.1.7.10+dfsg-1~deb12u22:6.1.7.10+dfsg-1~deb12u2
rubyonrailsrails>= 0 < 2:7.2.2.2+dfsg-2~deb13u12:7.2.2.2+dfsg-2~deb13u1
rubyonrailsrails>= 0 < 2:7.2.2.2+dfsg-12:7.2.2.2+dfsg-1

Detection & IOCsextracted from sources · hover to see the quote

  • Detect Rails Active Storage image transformation requests where user-supplied input is passed directly as transformation methods or parameters (e.g., via params[:v]) to image_processing with mini_magick backend — flag requests where transformation arguments contain shell metacharacters or command sequences
  • This vulnerability is only exploitable when Active Storage is used together with the image_processing gem AND mini_magick as the image processor — scope detection to applications meeting both conditions
  • ·Exploitation is NOT possible in default Active Storage configurations — the vulnerable condition requires application code to explicitly pass untrusted user input as image transformation methods or parameters
  • ·Consuming user-supplied input for image transformation methods or their parameters is explicitly unsupported and dangerous behavior in Active Storage

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa9.2CRITICAL
osv9.2CRITICAL
vendor_debian9.2CRITICAL
vendor_redhat9.2CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.