HackerOne Disclosed Reports - 2026-05-07

0 Replies, 8 Views

Logo
Medium
resolved

ActiveStorage Disk Service Path Traversal via Custom Blob Key Injection


Bug reported by kim siwong was disclosed at May 7, 2026, 2:04 pm   |   Path Traversal

A vulnerability was discovered in the ActiveStorage Disk Service component of Ruby on Rails. The vulnerability allowed an attacker to achieve arbitrary file write, read, and delete on the server's filesystem by injecting a malicious blob key. The vulnerability was due to insufficient validation of the blob key parameter before constructing file paths. This could be exploited by an attacker who could influence the hash passed to the `.attach()` method.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-05-07 - by hashXploiter - 5 hours ago



Users browsing this thread: 1 Guest(s)