Skip to content

Possible path traversal in ActiveRecord::Tenanted::Storage::DiskService#path_for

Low
flavorjones published GHSA-pmwx-rm49-xv39 Jun 8, 2026

Package

bundler activerecord-tenanted (RubyGems)

Affected versions

< 0.7.0

Patched versions

0.7.0

Description

Summary

Active Record Tenanted's override of Active Storage's DiskService#path_for does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. ../) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected.

Mitigation

Upgrade to Active Record Tenanted v0.7.0 or later.

As a workaround, do not use untrusted user input as blob keys. Blob keys are expected to be trusted strings.

Credit

This issue was responsibly reported by @tonghuaroot.

References

Severity

Low

CVE ID

No known CVE

Weaknesses

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Learn more on MITRE.

Credits