CVE-2026-33173 | rails activestorage prior 7.2.3.1/8.0.4.1/8.1.2.1 DirectUploadsController intent by broadcast receiver (GHSA-qcfx-2mfw-w4cg)
A vulnerability categorized as problematic has been discovered in rails activestorage. Affected is the function DirectUploadsController. The manipulation results in improper verification of intent by broadcast receiver.
This vulnerability is identified as CVE-2026-33173. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.