Vulnerability GHSA-47m2-wp7j-p9vc
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
24 days ago
September 03, 2026 at 09:31 PM UTC
rubyzip path traversal vulnerability
0.5.7 - 3.3.1
0.5.7 - 3.3.1
Summary
rubyzip path traversal vulnerability
Details
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
6 years ago
Rubyzip denial of service
0.5.7 - 1.2.4 GHSA-5m2v-hc64-56h6
0.5.7 - 1.2.4 GHSA-5m2v-hc64-56h6
Critical
8 years ago
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
0.5.7 - 1.2.1 GHSA-vqcq-mrmw-mcmg
0.5.7 - 1.2.1 GHSA-vqcq-mrmw-mcmg
Critical
8 years ago
Directory traversal vulnerability in RubyZip
0.5.7 - 1.2.0 GHSA-gcqq-w6gr-h9j9
0.5.7 - 1.2.0 GHSA-gcqq-w6gr-h9j9
Impacted packages
Timeline
Published
24 days ago
September 03, 2026 at 09:31 PM UTC
Fixed (3.4.0)
3 months ago
June 14, 2026 at 10:18 AM UTC
Last Modified
2 days ago
September 25, 2026 at 07:45 PM UTC