Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5601 articles · 220742 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-53769PATCHED
rubygems · avo

Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy

Description

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_<field>? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0.

Affected Products

VendorProductVersions
rubygemsavo>= 2.28.0, < 3.32.0

References

  • https://github.com/avo-hq/avo/security/advisories/GHSA-pqpw-cvm4-8mv9(x_refsource_CONFIRM)
  • https://github.com/avo-hq/avo/pull/4520(x_refsource_MISC)
  • https://github.com/avo-hq/avo/commit/de12070dbac0cb6a7e2bea357f9697f99e92554c(x_refsource_MISC)
  • https://github.com/avo-hq/avo/releases/tag/v3.32.0(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB17d ago
CVE-2026-53769 | avo-hq Avo up to 3.31.x Attachment Upload Endpoint improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.16.5 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
avo@3.32.0
CWECWE-862, CWE-863
PublishedJul 9, 2026
Tags
GHSA-pqpw-cvm4-8mv9rubygems
Trending Score4
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-44163
fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`
Trending: 15
NONECVE-2026-66066EXPKEV
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Trending: 13
HIGHCVE-2026-50276
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
Trending: 13
MEDIUMCVE-2026-54171
Excon: redact additional sensitive/risky headers when following redirects
Trending: 10
LOWCVE-2026-44162
fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3`
Trending: 6

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 9, 2026
Discovered by ZDM
Jul 9, 2026
Patch Available
Sep 9, 2026