CVE-2026-85396 | rubyzip up to 3.3.x Path Validation Zip::Entry#extract path traversal
A vulnerability, which was classified as problematic, was found in rubyzip up to 3.3.x. Impacted is the function Zip::Entry#extract of the component Path Validation. The manipulation results in path traversal.
This vulnerability was named CVE-2026-85396. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More