Junglewise Threat Intelligence

CVE-2026-45378: Decidim sensitive document exposure via reusable Active Storage links

CVE-2026-45378 · Severity: high · CVSS 7.5 · Published 2026-07-13

Vendors: Decidim.

Executive brief

Decidim is a participatory democracy platform used by public institutions and organizations. A vulnerability in its identity verification system allows sensitive documents, such as scanned ID cards, to be accessed by unauthorized parties via reusable links. These links remain valid for seven days and can be leaked through browser history, logs, or screenshots, potentially leading to the exposure of highly sensitive personal information.

Technical details

The Decidim verification admin UI exposes scanned identity documents using reusable Active Storage disk links generated via 'variant_url(...)'. These links bypass standard authorization-checking controllers and are signed to remain valid for seven days by default. Because the signed URL acts as the sole credential, any party that obtains the link (e.g., through browser history, server logs, or analytics) can download the 'verification_attachment' blobs without authentication. The vulnerability affects the 'decidim-verifications' gem in versions prior to 0.30.9, 0.31.5, and 0.32.0. Patches have been released to route these files through proper authorization checks.

Affected products

  • Decidim decidim-verifications < 0.30.9, >= 0.31.0.rc1, < 0.31.5, >= 0.32.0.rc1, < 0.32.0

Timeline

  • 2026-07-13: advisory: GitHub Advisory published
  • 2026-07-13: patched: Fixes released in versions 0.30.9, 0.31.5, and 0.32.0

References