rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.

Project Subscriptions

Vendors Products
Rubyzip Project Subscribe
Rubyzip Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like ../upload_backup/owned.sh to write files outside the intended extraction directory into sibling paths sharing the destination prefix.
Title rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix
First Time appeared Rubyzip Project
Rubyzip Project rubyzip
Weaknesses CWE-22
CPEs cpe:2.3:a:rubyzip_project:rubyzip:*:*:*:*:*:*:*:*
Vendors & Products Rubyzip Project
Rubyzip Project rubyzip
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-03T19:00:09.867Z

Reserved: 2026-09-03T18:10:59.168Z

Link: CVE-2026-85396

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T19:17:31.527

Modified: 2026-09-03T19:17:31.527

Link: CVE-2026-85396

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses