Vulnerability GHSA-47m2-wp7j-p9vc

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
24 days ago
September 03, 2026 at 09:31 PM UTC
rubyzip path traversal vulnerability
0.5.7 - 3.3.1
0.5.7 - 3.3.1

Summary

rubyzip path traversal vulnerability

Details

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.

Impacted packages

Timeline

Published
24 days ago
September 03, 2026 at 09:31 PM UTC
Fixed (3.4.0)
3 months ago
June 14, 2026 at 10:18 AM UTC
Last Modified
2 days ago
September 25, 2026 at 07:45 PM UTC