{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rubygems/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-82455"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RubyGems"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["RubyGems"],"content_html":"\u003cp\u003eRubyGems is vulnerable to a path traversal flaw during the gem extraction process, tracked as CVE-2026-82455. The vulnerability arises because RubyGems fails to re-validate path containment after resolving filesystem symlinks during package installation. An attacker can craft a malicious gem containing a symlink that points to a location outside the designated extraction root. If this symlink is placed within the destination directory, subsequent file extraction operations may follow the link, allowing the attacker to overwrite or create files in arbitrary locations on the host filesystem with the privileges of the user running the gem installation command. This could lead to remote code execution (RCE) if an attacker can overwrite critical system binaries, configuration files, or startup scripts. Defenders should update their RubyGems environments immediately to ensure proper path validation and symlink checks are enforced.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for arbitrary file write on the host filesystem, potentially leading to privilege escalation or remote code execution. This impacts any user or CI/CD system that executes 'gem install' on untrusted or maliciously crafted gem files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate RubyGems to the patched version that incorporates the fix for CVE-2026-82455 to ensure that the real path of the parent directory is validated before file operations occur.\u003c/li\u003e\n\u003cli\u003eImplement sandboxing or containerization for gem installation processes to limit the scope of potential file system access.\u003c/li\u003e\n\u003cli\u003eMonitor build pipelines for unexpected file writes originating from gem installation processes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T17:40:42Z","date_published":"2026-08-29T17:40:42Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rubygems-path-traversal/","summary":"A path traversal vulnerability in RubyGems allows maliciously crafted gems to write files outside the intended extraction directory by exploiting improper symlink validation.","title":"CVE-2026-82455 - Path Traversal in RubyGems Extraction Process","url":"https://feed.craftedsignal.io/briefs/2026-08-rubygems-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - RubyGems","version":"https://jsonfeed.org/version/1.1"}