Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44837

Опубликовано: 26 мая 2026
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
EPSS Низкий

Описание

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:viewcomponent:view_component:*:*:*:*:*:ruby:*:*
Версия от 3.0.0 (включая) до 4.9.0 (исключая)

EPSS

Процентиль: 34%
0.00412
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-187

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

CVSS3: 5.9
debian
3 месяца назад

view_component is a framework for building reusable, testable, and enc ...

CVSS3: 5.9
github
3 месяца назад

view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

EPSS

Процентиль: 34%
0.00412
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-187