{"id":"CVE-2023-49090","aliases":["GHSA-gxhx-g4fq-49hj"],"url":"https://o3.security/vulnerability/CVE-2023-49090","summary":"CarrierWave has a content-type allowlist bypass vulnerability, possibly leading to XSS","details":"CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.","published":"2023-11-29T14:38:52.195Z","modified":"2026-07-15T01:48:54.322614596Z","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"carrierwave","fixedVersion":"3.0.5"},{"ecosystem":"RubyGems","name":"carrierwave","fixedVersion":"2.2.5"}],"fix":{"url":"https://github.com/carrierwaveuploader/carrierwave/commit/39b282db5c1303899b3d3381ce8a837840f983b5","label":"carrierwaveuploader/carrierwave@39b282d"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49090.json"},{"type":"ADVISORY","url":"https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-gxhx-g4fq-49hj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49090"},{"type":"FIX","url":"https://github.com/carrierwaveuploader/carrierwave/commit/39b282db5c1303899b3d3381ce8a837840f983b5"},{"type":"FIX","url":"https://github.com/carrierwaveuploader/carrierwave/commit/863d425c76eba12c3294227b39018f6b2dccbbf3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:54.322614596Z"}}