CVE-2026-54659

Source
https://cve.org/CVERecord?id=CVE-2026-54659
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54659.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54659
Aliases
Published
2026-07-28T22:25:35.231Z
Modified
2026-07-30T04:02:35.771986828Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Pagy I18n locale option is not validated before being used in a file path
Details

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54659.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/ddnexus/pagy

Affected ranges

Type
GIT
Repo
https://github.com/ddnexus/pagy
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "43.0.0"
        },
        {
            "fixed": "43.5.6"
        }
    ]
}

Affected versions

43.*
43.0.0
43.0.1
43.0.2
43.0.3
43.0.4
43.0.5
43.0.6
43.0.7
43.1.0
43.1.1
43.1.2
43.1.3
43.1.4
43.1.5
43.1.6
43.1.7
43.1.8
43.2.0
43.2.1
43.2.10
43.2.2
43.2.3
43.2.4
43.2.5
43.2.6
43.2.7
43.2.8
43.2.9
43.3.0
43.3.1
43.3.2
43.3.3
43.4.0
43.4.1
43.4.2
43.4.3
43.4.4
43.5.0
43.5.1
43.5.2
43.5.3
43.5.4
43.5.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54659.json"