{"id":"CVE-2025-55193","aliases":["GHSA-76r7-hhxj-r776"],"url":"https://o3.security/vulnerability/CVE-2025-55193","summary":"Active Record logging vulnerable to ANSI escape injection","details":"This vulnerability has been assigned the CVE identifier CVE-2025-55193\n\n### Impact\nThe ID passed to `find` or similar methods may be logged without escaping. If this is directly to the terminal it may include unescaped ANSI sequences.\n\n### Releases\nThe fixed releases are available at the normal locations.\n\n### Credits\n\nThanks to [lio346](https://hackerone.com/lio346) from Unit 515 of OPSWAT for reporting this vulnerability","published":"2025-08-13T22:41:41.890Z","modified":"2026-09-09T03:45:13.249544763Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"activerecord","fixedVersion":"8.0.2.1"},{"ecosystem":"RubyGems","name":"activerecord","fixedVersion":"7.2.2.2"},{"ecosystem":"RubyGems","name":"activerecord","fixedVersion":"7.1.5.2"}],"fix":{"url":"https://github.com/rails/rails/commit/3beef20013736fd52c5dcfdf061f7999ba318290","label":"rails/rails@3beef20"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55193.json"},{"type":"ADVISORY","url":"https://github.com/rails/rails/security/advisories/GHSA-76r7-hhxj-r776"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55193"},{"type":"FIX","url":"https://github.com/rails/rails/commit/3beef20013736fd52c5dcfdf061f7999ba318290"},{"type":"FIX","url":"https://github.com/rails/rails/commit/568c0bc2f1e74c65d150a84b89a080949bf9eb9b"},{"type":"FIX","url":"https://github.com/rails/rails/commit/6a944ca4805e72050a0fbb1a461534eb760d3202"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activerecord/CVE-2025-55193.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T03:45:13.249544763Z"}}