activerecord-tenanted
Enable a Rails application to have separate databases for each tenant.
Activity
- Latest release
- 1mo ago
- Total releases
- 9
- Cadence
- ~16 days
- Last 12 months
- 4
Reach
- Downloads
- 16.7k
- Stars
- 611
Details
- License
- MIT
- First release
- Aug 25, 2025
| Version | Released | |
|---|---|---|
0.8.0
minor
| ||
0.7.0
minor
| ||
0.6.0
minor
1 CVE
GHSA-pmwx-rm49-xv39
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
Network
High
Low
None
SummaryActive Record Tenanted's override of Active Storage's MitigationUpgrade to Active Record Tenanted v0.7.0 or later. As a workaround, do not use untrusted user input as blob keys. Blob keys are expected to be trusted strings. CreditThis issue was responsibly reported by @tonghuaroot. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
Fixed in
0.7.0
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
GHSA-pmwx-rm49-xv39
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
Network
High
Low
None
SummaryActive Record Tenanted's override of Active Storage's MitigationUpgrade to Active Record Tenanted v0.7.0 or later. As a workaround, do not use untrusted user input as blob keys. Blob keys are expected to be trusted strings. CreditThis issue was responsibly reported by @tonghuaroot. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
Fixed in
0.7.0
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
GHSA-pmwx-rm49-xv39
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
Network
High
Low
None
SummaryActive Record Tenanted's override of Active Storage's MitigationUpgrade to Active Record Tenanted v0.7.0 or later. As a workaround, do not use untrusted user input as blob keys. Blob keys are expected to be trusted strings. CreditThis issue was responsibly reported by @tonghuaroot. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
Fixed in
0.7.0
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
GHSA-pmwx-rm49-xv39
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
Network
High
Low
None
SummaryActive Record Tenanted's override of Active Storage's MitigationUpgrade to Active Record Tenanted v0.7.0 or later. As a workaround, do not use untrusted user input as blob keys. Blob keys are expected to be trusted strings. CreditThis issue was responsibly reported by @tonghuaroot. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
Fixed in
0.7.0
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
GHSA-pmwx-rm49-xv39
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
Network
High
Low
None
SummaryActive Record Tenanted's override of Active Storage's MitigationUpgrade to Active Record Tenanted v0.7.0 or later. As a workaround, do not use untrusted user input as blob keys. Blob keys are expected to be trusted strings. CreditThis issue was responsibly reported by @tonghuaroot. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
Fixed in
0.7.0
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
GHSA-pmwx-rm49-xv39
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
Network
High
Low
None
SummaryActive Record Tenanted's override of Active Storage's MitigationUpgrade to Active Record Tenanted v0.7.0 or later. As a workaround, do not use untrusted user input as blob keys. Blob keys are expected to be trusted strings. CreditThis issue was responsibly reported by @tonghuaroot. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
Fixed in
0.7.0
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
GHSA-pmwx-rm49-xv39
Jul 29, 2026
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
Network
High
Low
None
SummaryActive Record Tenanted's override of Active Storage's MitigationUpgrade to Active Record Tenanted v0.7.0 or later. As a workaround, do not use untrusted user input as blob keys. Blob keys are expected to be trusted strings. CreditThis issue was responsibly reported by @tonghuaroot. Affected versions
0.1.0
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
Fixed in
0.7.0
References
Updated Jul 29, 2026 · Source: OSV.dev |