Executive brief
CarrierWave, a popular file upload framework for Ruby applications, contains a flaw in its file-type blocking mechanism. This vulnerability allows attackers to bypass security filters and upload restricted file types, such as SVG images containing malicious scripts. If these files are then viewed by other users, it can lead to unauthorized actions or data theft through Cross-Site Scripting (XSS).
Technical details
A vulnerability exists in CarrierWave's `content_type_denylist` (and the deprecated `content_type_blacklist`) where string entries are interpolated directly into a regular expression without escaping or anchoring. Specifically, in `lib/carrierwave/uploader/content_type_denylist.rb`, the code uses `content_type =~ /#{item}/`. For MIME types containing regex metacharacters like 'image/svg+xml', the '+' is interpreted as a quantifier rather than a literal character, causing the match to fail. An attacker can exploit this by uploading a malicious SVG file that bypasses the denylist. If the application serves the SVG inline, it results in stored Cross-Site Scripting (XSS). The issue is fixed in versions 2.2.7 and 3.1.3 by implementing `Regexp.quote` and `\A` anchoring.
Affected products
- carrierwaveuploader CarrierWave < 2.2.7, >= 3.0.0.rc < 3.1.3
Timeline
- 2026-05-23: advisory: GitHub Security Advisory published
- 2026-06-17: disclosed: CVE-2026-44587 published to NVD
- 2026-06-17: patched: Fixes released in versions 2.2.7 and 3.1.3