Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2xmw-f8j8-wfxc | Pagy I18n locale option is not validated before being used in a file path |
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ddnexus
Ddnexus pagy |
|
| Vendors & Products |
Ddnexus
Ddnexus pagy |
Wed, 29 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6. | |
| Title | Pagy I18n locale option is not validated before being used in a file path | |
| Weaknesses | CWE-200 CWE-22 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-29T13:06:59.870Z
Reserved: 2026-06-15T20:16:46.199Z
Link: CVE-2026-54659
Updated: 2026-07-29T13:04:54.779Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T15:10:27Z
Github GHSA