Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.
History

Thu, 14 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Rails
Rails rails
Vendors & Products Rails
Rails rails

Thu, 14 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

threat_severity

Moderate


Wed, 13 Aug 2025 23:00:00 +0000

Type Values Removed Values Added
Description Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.
Title Active Record logging vulnerable to ANSI escape injection
Weaknesses CWE-150
References
Metrics cvssV4_0

{'score': 2.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:U'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-13T22:41:41.890Z

Updated: 2025-08-14T14:51:11.284Z

Reserved: 2025-08-08T21:55:07.963Z

Link: CVE-2025-55193

cve-icon Vulnrichment

Updated: 2025-08-14T13:42:11.881Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-13T23:15:26.237

Modified: 2025-08-14T13:11:53.633

Link: CVE-2025-55193

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-13T22:41:41Z

Links: CVE-2025-55193 - Bugzilla