Launch Week Day 1: Announcing Security Design Review
UNKNOWN RubyGems

Active Record logging vulnerable to ANSI escape injection

GHSA-76r7-hhxj-r776 · CVE-2025-55193

Published · Modified

Description

This vulnerability has been assigned the CVE identifier CVE-2025-55193

Impact

The ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences.

Releases

The fixed releases are available at the normal locations.

Credits

Thanks to lio346 from Unit 515 of OPSWAT for reporting this vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes