Vendor
rubyzip versions before 3.4.0 are vulnerable to path traversal within the Zip::Entry#extract method, allowing attackers to write files outside the intended directory via malicious archive entries.