{"id":"CVE-2026-54659","summary":"Pagy I18n locale option is not validated before being used in a file path","details":"Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as \u003clocale\u003e.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.","aliases":["GHSA-2xmw-f8j8-wfxc"],"modified":"2026-07-31T03:34:12.692237426Z","published":"2026-07-28T22:25:35.231Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54659.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-200","CWE-22"]},"references":[{"type":"WEB","url":"https://github.com/ddnexus/pagy/releases/tag/43.5.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54659.json"},{"type":"ADVISORY","url":"https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54659"},{"type":"FIX","url":"https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df"},{"type":"FIX","url":"https://github.com/ddnexus/pagy/pull/908"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ddnexus/pagy","events":[{"introduced":"c59c084087b3dbb02dd637d87e1e1254ac6cfa8d"},{"fixed":"efcf09690e9fa7d7abdfb987b785a55f87e287df"},{"fixed":"ef90524ef31ae03c0c57755d1d462f4233aab22f"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"43.0.0"},{"fixed":"43.5.6"}]}}],"versions":["43.5.5","43.5.4","43.5.3","43.5.2","43.5.1","43.5.0","43.4.4","43.4.3","43.4.2","43.4.1","43.4.0","43.3.3","43.3.2","43.3.1","43.3.0","43.2.10","43.2.9","43.2.8","43.2.7","43.2.6","43.2.5","43.2.4","43.2.3","43.2.2","43.2.1","43.2.0","43.1.8","43.1.7","43.1.6","43.1.5","43.1.4","43.1.3","43.1.2","43.1.1","43.1.0","43.0.7","43.0.6","43.0.5","43.0.4","43.0.3","43.0.2","43.0.1","43.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54659.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}