CVE-2026-34060
Ruby LSP has arbitrary code execution through branch setting
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
7th
Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace setting was interpolated without sanitization into a generated Gemfile, allowing arbitrary Ruby code execution when a user opens a project containing a malicious .vscode/settings.json. This issue has been patched in Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9.
| CWE | CWE-94 |
| Vendor | shopify |
| Product | ruby-lsp |
| Published | Mar 31, 2026 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for shopify ruby-lsp
Be the first to know when new critical vulnerabilities affecting shopify ruby-lsp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Shopify / ruby-lsp
< 0.26.9
Shopify / Shopify.ruby-lsp
< 0.10.2