216.73.216.233

CVE-2026-44837

· Published 26/05/2026 21:16 · Modified 26/05/2026 21:16

Labels: CVE-2026-44837 2026-05-26CVE-2026-44837CWE-187[email protected]

Essential information

Published
26/05/2026 21:16
Modified
26/05/2026 21:16
Author
Creator
CVSS
5.9 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
rails / view component cpe:2.3:a:rails:view_component:3.0.0-4.9.0:*:*:*:*:*:*:*

References