Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44837

Опубликовано: 26 мая 2026
Источник: debian
EPSS Низкий

Описание

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-view-componentfixed4.12.0-1package
ruby-view-componentpostponedbookwormpackage

Примечания

  • https://github.com/ViewComponent/view_component/security/advisories/GHSA-hg3h-g7xc-f7vp

EPSS

Процентиль: 34%
0.00412
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

CVSS3: 5.9
nvd
3 месяца назад

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

CVSS3: 5.9
github
3 месяца назад

view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

EPSS

Процентиль: 34%
0.00412
Низкий