THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-82455 (HIGH 7.1) — RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can

[NVD] CVE-2026-82455 (HIGH 7.1) — RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can

mednvdPublished 2026-08-29

CVE-2026-82455 CVSS: 7.1 HIGH Published: 2026-08-29T14:16:38.623

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can instead be written outside of it, breaking the extrac

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82455