rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rubyzip
Rubyzip rubyzip |
|
| Vendors & Products |
Rubyzip
Rubyzip rubyzip |
Fri, 04 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 03 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix. | |
| Title | rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix | |
| First Time appeared |
Rubyzip Project
Rubyzip Project rubyzip |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:rubyzip_project:rubyzip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rubyzip Project
Rubyzip Project rubyzip |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-03T18:54:27.903Z
Updated: 2026-09-03T19:00:09.867Z
Reserved: 2026-09-03T18:10:59.168Z
Link: CVE-2026-85396
Updated: 2026-09-03T19:00:04.473Z
Status : Received
Published: 2026-09-03T19:17:31.527
Modified: 2026-09-03T19:17:31.527
Link: CVE-2026-85396