CVE-2026-45377 (decidim-core): Decidim - Private exports can be downloaded through reusable links
21-Jul-2026 1
Originally appeared on RubySec.## Description The normal `download_your_data` flow requires the requester to be logged in as the export owner, but the resulting Active Storage blob redirect URL can be replayed without authentication by anyone who obtains it. ## Impact Personal...
CVE-2026-45377 (decidim-core): Decidim - Private exports can be downloaded through reusable links #ruby #rubydeveloper #rubyonrails #ruby #rubyonrails #programming #webdev #cve-2026-45377 #(decidim-core): https://www.rubyonrails.ba/link/cve-2026-45377-decidim-core-decidim-private-exports-can-be-downloaded-through-reusable-links