CVE-2025-55193
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-55193
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-55193.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 2:6.1.7.10+dfsg-1~deb12u2 |
| debian | bullseye | fixed | 2:6.0.3.7+dfsg-2+deb11u4 |
| debian | forky | fixed | 2:7.2.2.2+dfsg-1 |
| debian | sid | fixed | 2:7.2.2.2+dfsg-1 |
| debian | trixie | fixed | 2:7.2.2.2+dfsg-2~deb13u1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| RubyGems | activerecord | <~> 7.1.5, >= 7.1.5.2 | ~> 7.1.5, >= 7.1.5.2 |
| RubyGems | activerecord | >=8.0,<8.0.2.1 | 8.0.2.1 |
| RubyGems | activerecord | >=7.2,<7.2.2.2 | 7.2.2.2 |
| RubyGems | activerecord | <7.1.5.2 | 7.1.5.2 |
References
- https://github.com/rails/rails/security/advisories/GHSA-76r7-hhxj-r776
- https://www.suse.com/security/cve/CVE-2025-55193.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-55193
- https://github.com/rails/rails/commit/3beef20013736fd52c5dcfdf061f7999ba318290
- https://github.com/rails/rails/commit/568c0bc2f1e74c65d150a84b89a080949bf9eb9b
- https://github.com/rails/rails/commit/6a944ca4805e72050a0fbb1a461534eb760d3202
- https://github.com/rails/rails
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2025-55193.yml
- https://security-tracker.debian.org/tracker/CVE-2025-55193
Verify integrity in audit chain (admin only). AS-IS.