Active Storage's DirectUploadsController accepts arbitrary metadata from the client and persists it on the blob. Because internal flags like identified and analyzed are stored in the same metadata hash, a malicious direct-upload client could set these flags.
The fixed releases are available at the normal locations.
This was responsible reported by Hackerone researcher pwnie
{
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2026-03-24T00:16:28Z",
"cwe_ids": [
"CWE-925"
],
"github_reviewed_at": "2026-03-23T20:54:16Z"
}