CVE-2025-55193
CVE-2025-55193 — Active Record logging vulnerable to ANSI escape injection
Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.
Published Updated Sources: cvelistV5, GitHub_M
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
1%
chance of exploitation in 30 days
CVSS base
2.7
LOW
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
None
none · proof-of-concept · active
Automatable
Yes
can an attacker script all four kill-chain steps
Technical impact
Partial
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (1)
Products (1)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 2.7 | CVSS 4.0 | LOW | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-150
References
4 on the record
- github.com/rails/rails/security/advisories/GHSA-76r7-hhxj-r776
x_refsource_CONFIRM
- github.com/rails/rails/commit/3beef20013736fd52c5dcfdf061f7999ba318290
x_refsource_MISC
- github.com/rails/rails/commit/568c0bc2f1e74c65d150a84b89a080949bf9eb9b
x_refsource_MISC
- github.com/rails/rails/commit/6a944ca4805e72050a0fbb1a461534eb760d3202
x_refsource_MISC
Elsewhere on this site
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.