Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-45378PATCHED
rubygems · decidim-verifications

Decidim: Verification documents can be downloaded through reusable links

Description

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Active Storage disk URLs, allowing anyone who obtains a URL to download the scanned document without an authenticated Decidim session until the signature expires. Verification-document images are rendered with variant_url(...), which produces signed /rails/active_storage/disk/... links instead of routing the file through an authorization-checking controller. Because Decidim configures Active Storage service URLs to remain valid for seven days, the URL itself becomes the credential for that period. The affected files are verification_attachment blobs on Decidim::Authorization, and the admin review pages embed those signed URLs directly into the HTML for pending and confirmation views. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.

Affected Products

VendorProductVersions
rubygemsdecidim-verifications< 0.30.9, >= 0.31.0.rc1, < 0.31.5, >= 0.32.0.rc1, < 0.32.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
rubygemsdecidim-verificationsGHSA85%

References

  • https://github.com/decidim/decidim/security/advisories/GHSA-3mvf-82qp-8qh5(x_refsource_CONFIRM)

Related News (1 articles)

Tier C
VulDB17d ago
CVE-2026-45378 | Decidim up to 0.30.8/0.31.4/0.32.0.rc1 Identity-Document Verification Admin UI verification_attachment blobs improper authorization
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
decidim-verifications@0.30.9decidim-verifications@0.31.5decidim-verifications@0.32.0
CWECWE-200
PublishedJul 13, 2026
Tags
GHSA-3mvf-82qp-8qh5rubygems
Trending Score7
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Trending: 61
NONECVE-2026-61666
websocket-driver: Denial of service via malformed Host header
Trending: 8
NONECVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Trending: 6
HIGHCVE-2026-45414
Decidim: JWT-backed authentication can be replayed across organizations
Trending: 5
MEDIUMCVE-2026-45415
Decidim: CSV census record endpoints improper authorization
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 13, 2026
Discovered by ZDM
Jul 13, 2026
Patch Available
Aug 7, 2026