Code Execution Vulnerability in Ruby LSP VS Code Extension by Shopify
CVE-2026-48122

5.4MEDIUM

Key Information:

Vendor

Shopify

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-48122?

The Ruby LSP VS Code extension is susceptible to a vulnerability that allows an attacker to manipulate workspace-level settings via a malicious .vscode/settings.json file. If a developer opens and trusts this repository, it can redirect the execution paths for the Ruby executable, version manager executables, or Bundler Gemfile, potentially executing arbitrary code with the developer's privileges. This issue has been resolved in version 0.10.4.

Affected Version(s)

ruby-lsp < 0.10.4

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.