{"id":"CVE-2026-53769","aliases":["GHSA-pqpw-cvm4-8mv9"],"url":"https://o3.security/vulnerability/CVE-2026-53769","summary":"Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy","details":"Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_<field>? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0.","published":"2026-09-04T20:02:01.456Z","modified":"2026-09-11T03:30:51.044051901Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00254,"percentile":0.17086,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"avo","fixedVersion":"3.32.0"}],"fix":{"url":"https://github.com/avo-hq/avo/commit/de12070dbac0cb6a7e2bea357f9697f99e92554c","label":"avo-hq/avo@de12070"},"references":[{"type":"WEB","url":"https://github.com/avo-hq/avo/releases/tag/v3.32.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53769.json"},{"type":"ADVISORY","url":"https://github.com/avo-hq/avo/security/advisories/GHSA-pqpw-cvm4-8mv9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53769"},{"type":"FIX","url":"https://github.com/avo-hq/avo/commit/de12070dbac0cb6a7e2bea357f9697f99e92554c"},{"type":"FIX","url":"https://github.com/avo-hq/avo/pull/4520"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T03:30:51.044051901Z"}}