๐Ÿ” CVE Alert

CVE-2026-54659

UNKNOWN 0.0

Pagy I18n locale option is not validated before being used in a file path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.

CWE CWE-22 CWE-200
Vendor ddnexus
Product pagy
Published Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for ddnexus pagy

Be the first to know when new unknown vulnerabilities affecting ddnexus pagy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ddnexus / pagy
>= 43.0.0, < 43.5.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc github.com: https://github.com/ddnexus/pagy/pull/908 github.com: https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df github.com: https://github.com/ddnexus/pagy/releases/tag/43.5.6