{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rubyzip/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rubyzip_project:rubyzip:*:*:*:*:*:ruby:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85396"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rubyzip (\u003c 3.4.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["rubyzip"],"content_html":"\u003cp\u003erubyzip versions prior to 3.4.0 contain a critical path traversal vulnerability in the Zip::Entry#extract method. The library fails to perform robust validation when checking destination paths, specifically failing to account for cases where prefix comparison is performed without trailing directory separators. An attacker can create a specially crafted ZIP archive containing entries with path traversal sequences such as ../ in the filename. When an application using an affected version of rubyzip extracts such an archive, the library may incorrectly resolve the target path to a location outside the designated extraction directory. By targeting sensitive directories, an attacker could potentially overwrite configuration files, inject scripts into startup folders, or gain arbitrary code execution depending on the application's environment and permissions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized file writes on the host system. Depending on the target application's use case, this can lead to remote code execution, persistence, or configuration tampering. The vulnerability affects any application or service utilizing the rubyzip library for processing untrusted archive uploads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the rubyzip dependency to version 3.4.0 or later across all projects.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing rubyzip for file extraction to identify if archives are processed from untrusted user inputs.\u003c/li\u003e\n\u003cli\u003eImplement file path validation at the application level to ensure extracted file paths reside within the expected destination directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T19:23:10Z","date_published":"2026-09-03T19:23:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rubyzip-path-traversal/","summary":"rubyzip versions before 3.4.0 are vulnerable to path traversal within the Zip::Entry#extract method, allowing attackers to write files outside the intended directory via malicious archive entries.","title":"Path Traversal Vulnerability in rubyzip","url":"https://feed.craftedsignal.io/briefs/2026-09-rubyzip-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Rubyzip","version":"https://jsonfeed.org/version/1.1"}