VYPR
Critical severity9.8NVD Advisory· Published Feb 27, 2017· Updated Jun 17, 2026

CVE-2017-5946

CVE-2017-5946

Description

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
rubyzipRubyGems
< 1.2.11.2.1

Affected products

6

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.