THREAT OPS › Threat News › [NVD] CVE-2026-82455 (HIGH 7.1) — RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can
[NVD] CVE-2026-82455 (HIGH 7.1) — RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can
CVE-2026-82455 CVSS: 7.1 HIGH Published: 2026-08-29T14:16:38.623
RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can instead be written outside of it, breaking the extrac
Indicators of compromise
- CVE-2026-82455cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82455