Path Traversal Vulnerability in Pagy Pagination Library by ddnexus
CVE-2026-54659

6.9MEDIUM

Key Information:

Vendor

Ddnexus

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-54659?

The Pagy pagination library prior to version 43.5.6 contains a vulnerability where the Pagy::I18n.locale= method allows untrusted locale parameter values to manipulate file paths. This could lead to the exposure of sensitive YAML file contents through file existence checks, as attackers can leverage absolute paths and directory traversal sequences. The vulnerability has been addressed in version 43.5.6.

Affected Version(s)

pagy >= 43.0.0, < 43.5.6

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.