Active Storage Vulnerability in Decidim Framework Exposes Sensitive Identity Documents
CVE-2026-45378
What is CVE-2026-45378?
The Decidim framework, utilized for participatory democracy applications, has a vulnerability that unintentionally exposes sensitive identity documents via signed Active Storage URLs. Prior to specific version updates, the admin UI embedded these URLs, allowing unauthorized users to download verified documents without needing an authenticated session. This occurs due to the configuration of service URLs, which remain valid for seven days, effectively making the URL a temporary credential. This critical flaw can lead to potential data breaches, compromising the privacy of individuals whose identity documents are handled within the system. The issue has been resolved in versions 0.30.9, 0.31.5, and 0.32.0.rc2, urging users to upgrade to maintain data security.
Affected Version(s)
decidim < 0.30.9 < 0.30.9
decidim >= 0.31.0.rc1, < 0.31.5 < 0.31.0.rc1, 0.31.5
decidim >= 0.32.0.rc1, < 0.32.0 < 0.32.0.rc1, 0.32.0
