{"id":"CVE-2026-54659","aliases":["GHSA-2xmw-f8j8-wfxc"],"url":"https://o3.security/vulnerability/CVE-2026-54659","summary":"Pagy I18n locale option is not validated before being used in a file path","details":"Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.","published":"2026-07-28T22:25:35.231Z","modified":"2026-08-12T03:51:25.969968782Z","cvss":null,"epss":{"score":0.00368,"percentile":0.30128,"asOf":"2026-09-11"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"pagy","fixedVersion":"43.5.6"}],"fix":{"url":"https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df","label":"ddnexus/pagy@efcf096"},"references":[{"type":"WEB","url":"https://github.com/ddnexus/pagy/releases/tag/43.5.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54659.json"},{"type":"ADVISORY","url":"https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54659"},{"type":"FIX","url":"https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df"},{"type":"FIX","url":"https://github.com/ddnexus/pagy/pull/908"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:25.969968782Z"}}