CVE-2015-2963: Thoughtbot Paperclip

Medium severity, CVSS 4.3. EPSS: 2.1% chance of exploitation in the next 30 days.

The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and conduct cross-site scripting (XSS) attacks via a spoofed value, as demonstrated by image/jpeg.

Affected products

Published 2015-07-10. Last modified 2026-06-17.