CVE-2026-44837
5.9 MEDIUMview_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails
Published: 2026-05-26 · Last updated: 2026-06-02
Severity and scoring
- CVSS
- 5.9 MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-187
Affected products
| Vendor | Product |
|---|---|
| viewcomponent | view_component |
Description
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file path with File.realpath, then checks whether the resolved path starts with the temp directory path. This is not a safe containment check because sibling directories can share the same string prefix. This vulnerability is fixed in 4.9.0.
Source: NVD