Rubyzip is a focused Ruby library for reading and writing ZIP archives, widely embedded in applications that handle compressed file uploads and extraction. The durable weakness signal centers on path-traversal and symlink-following vulnerabilities that arise during archive handling—flaws that can allow malicious archives to write files outside their intended directory scope.
The number and severity of CVEs published that impact products developed by Rubyzip Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5946CRITICAL The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicio | Feb 27, 2017 | 9.8 | 32 | NO | NO |
CVE-2018-1000544CRITICAL rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This a | Jun 26, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-16892MEDIUM In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause | Sep 25, 2019 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rubyzip Project.
Media articles that mention a CVE ID that affects a product developed by Rubyzip Project — matched by CVE ID, not by vendor name.