CVE-2026-82455: RubyGems before 4.0.13 Path Traversal via Symlink Resolution
Rejected reason: The RubyGems maintainers determined that the reported symlink-following behavior during gem extraction is not a security vulnerability, so no vulnerability exists for this record to describe.
Other sources
RubyGems before 4.0.13 Path Traversal via Symlink Resolution
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.3.5-10
Event History
Frequently Asked Questions
Which installations are affected?
RubyGems versions earlier than 4.0.13 are affected. Version 4.0.13 changes extraction to resolve the parent directory's real path and reject paths that escape the destination directory.
What conditions are required for exploitation?
A symlink must already exist within the extraction destination directory and point outside the extraction root. Files extracted through that symlink can then be written outside the intended destination.
How can I assess exposure before upgrading?
Inspect gem extraction destination directories for pre-existing symlinks, particularly links whose resolved targets are outside the intended extraction root. Such symlinks are the condition that breaks the extraction boundary.