Back to CVE List

CVE-2026-54659

MEDIUM SEVERITY

Vulnerability Description

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.

Vulnerability Details

Published Date
Last Modified
Source
GitHub
Vendor
rubygems
Product
pagy

External References

Discussion (0)

Add Comment

No comments yet. Be the first!