Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-44837

3 месяца назад

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-44837

3 месяца назад

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-44837

3 месяца назад

view_component is a framework for building reusable, testable, and enc ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-hg3h-g7xc-f7vp

3 месяца назад

view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-44837

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

CVSS3: 5.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-44837

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

CVSS3: 5.9
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-44837

view_component is a framework for building reusable, testable, and enc ...

CVSS3: 5.9
0%
Низкий
3 месяца назад
github логотип
GHSA-hg3h-g7xc-f7vp

view_component: System Test Entry Point Path Check Allows Sibling Directory Escape

CVSS3: 5.9
0%
Низкий
3 месяца назад

Уязвимостей на страницу