CVE-2026-45378: Decidim: Verification documents can be downloaded through reusable links
Scanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed /rails/active_storage/disk/ URLs that can be fetched without any authenticated session.
Anyone who obtains one of those URLs can retrieve the document until the signature expires.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45378 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →