SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-82455

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

RubyGems is vulnerable due to improper validation of path containment after resolving filesystem symlinks during gem extraction, allowing extracted files to be written outside the intended destination directory. This can lead to unauthorized file access or modification, potentially compromising system integrity. Organizations using RubyGems, particularly those managing sensitive data or critical applications, should prioritize addressing this vulnerability to mitigate risks associated with file system exposure.

CVE
CVE-2026-82455
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: The RubyGems maintainers determined that the reported symlink-following behavior during gem extraction is not a security vulnerability, so no vulnerability exists for this record to describe.