CVE-2025-55193

LOW

Active Record <7.1.5.2, <7.2.2.2, <8.0.2.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Active Record connects classes to relational database tables. Prior to versions 7.1.5.2, 7.2.2.2, and 8.0.2.1, the ID passed to find or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences. This issue has been patched in versions 7.1.5.2, 7.2.2.2, and 8.0.2.1.

Scores

CVSS v4 2.7
EPSS 0.0024
EPSS Percentile 47.3%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:U

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-150
Status published
Products (4)
rails/rails >= 0, < 7.1.5.2
rails/rails >= 7.2, < 7.2.2.2
rails/rails >= 8.0, < 8.0.2.1
rubygems/activerecord 8.0 - 8.0.2.1RubyGems
Published Aug 13, 2025
Tracked Since Feb 18, 2026