{"id":"CVE-2019-3881","aliases":["GHSA-g98m-96g9-wfjq"],"url":"https://o3.security/vulnerability/CVE-2019-3881","summary":"Insecure path handling in Bundler","details":"Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.","published":"2020-09-04T12:15:10.387Z","modified":"2026-08-27T08:15:03.527421Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"bundler","fixedVersion":"2.1.0"}],"fix":null,"references":[{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1651826"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:15:03.527421Z"}}