Description
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
Published: 2026-09-03
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Rubyzip
Rubyzip rubyzip
Vendors & Products Rubyzip
Rubyzip rubyzip

Fri, 04 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 03 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
Title rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix
First Time appeared Rubyzip Project
Rubyzip Project rubyzip
Weaknesses CWE-22
CPEs cpe:2.3:a:rubyzip_project:rubyzip:*:*:*:*:*:*:*:*
Vendors & Products Rubyzip Project
Rubyzip Project rubyzip
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Rubyzip Rubyzip
Rubyzip Project Rubyzip
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T19:00:09.867Z

Reserved: 2026-09-03T18:10:59.168Z

Link: CVE-2026-85396

cve-icon Vulnrichment

Updated: 2026-09-03T19:00:04.473Z

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:31.527

Modified: 2026-09-03T19:17:31.527

Link: CVE-2026-85396

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-03T18:54:27Z

Links: CVE-2026-85396 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:22:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')