All verified exploits

CVE-2026-33195 Server File Read via Active Storage Path Traversal

Deterministic critical Ruby on Rails Added cve-verified-cve-2026-33195

Detects Rails applications using Active Storage DiskService where the path_for method does not validate blob keys for directory traversal sequences. An attacker with access to the disk endpoint can craft a key containing ../../ to read arbitrary files from the server, including database credentials, encryption keys, and private configuration. Affects Rails < 7.2.3.1, 8.0.x < 8.0.4.1, and 8.1.x < 8.1.2.1.

Is your app exploitable through CVE-2026-33195?

Scan your domain free