AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-33564

CRITICAL · CVSS 9.8 EPSS 72.25% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-05-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2021-33564
Severity
CRITICAL
CVSS
9.8
EPSS
72.25%

Original NVD Description

An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The problem occurs because the generate and process features mishandle use of the ImageMagick convert utility.