CVE-2026-54659
MEDIUM SEVERITYVulnerability Description
Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
rubygems
Product
pagy
Discussion (0)
Add Comment
No comments yet. Be the first!