CVE-2026-85396 rubyzip versions before 3.4.0 contain a path traversal… — CVE Notify — TG.ME

🚨 CVE-2026-85396
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.

🎖@cveNotify
GitHub
oss/rubyzip.md at main · geo-chen/oss
securing oss responsibly. Contribute to geo-chen/oss development by creating an account on GitHub.
September 3, 2026 31