{"id":"GHSA-2xmw-f8j8-wfxc","summary":"Pagy I18n locale option is not validated before being used in a file path","details":"### Summary\n\n`Pagy::I18n.locale=` did not validate its argument before using it as a\npath component to load the matching dictionary file (`\u003clocale\u003e.yml`). An\napplication that assigns untrusted input to the locale — e.g. the common\npattern `Pagy::I18n.locale = params[:locale]` — let that input influence\nwhich file Pagy attempted to load.\n\n### Details\n\nThe setter stored the value as-is, and the loader joined it into a path\nand read it:\n\n```ruby\n# gem/lib/pagy/modules/i18n/i18n.rb\ndef locale=(value)\n  Thread.current[:pagy_locale] = value.to_s\nend\n\n# ...later, when translating:\npath = pathnames.reverse.map { |p| p.join(\"#{locale}.yml\") }.find(&:exist?)\ndictionary = YAML.load_file(path)[locale]\n```\n\nBecause the locale was used verbatim, a value such as an absolute path or\na `../`-style string redirected the lookup outside the locales directory.\nPagy's subsequent structural check (`dictionary['pagy']['p11n']`)\nprevents the file's contents from being returned, so this is **not** a\ndirect file read.\n\nFixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:\n\n```ruby\nLOCALE_PATTERN = /\\A[a-zA-Z]{2,8}(-[a-zA-Z0-9]{1,8})*\\z/\n\ndef locale=(value)\n  Thread.current[:pagy_locale] = value.to_s[LOCALE_PATTERN]\nend\n```\n\nAny non-matching value (including `nil`) resolves to the default locale\nand never reaches the file lookup.\n\n### PoC\n\nIn an application that sets `Pagy::I18n.locale = params[:locale]`, the\nloader appends `.yml` and reads `\u003clocale\u003e.yml`, so the request param\ncontrols the target path. For example, pointing it at the app's\n`config/database.yml`:\n\n1. Send a request with `?locale=../../../config/database` (adjust the\n   number of `../` to reach the app root from the gem's `locales/`\n   directory).\n2. Pagy calls `YAML.load_file` on the resulting `…/config/database.yml`.\n3. The outcome differs by whether that `.yml` exists, is readable, parses\n   as YAML, and has Pagy's expected structure — an existing, readable\n   `config/database.yml` raises a different error than a non-existent\n   path (which silently falls back to the default locale). This yields a\n   file-existence / readability oracle for `.yml` paths, and the targeted\n   file is read into the process during the attempt.\n\n### Impact\n\nInformation disclosure (CWE-22 / CWE-200): a file-existence / readability\noracle for `.yml` paths on the host, plus a server-side read of\nattacker-chosen files into the process. The file contents are not\nreturned in the response.\n\nOnly applications that pass **unsanitized end-user input** into\n`Pagy::I18n.locale=` are affected. Applications that set the locale from\ntrusted values are not affected.\n\n**Patched:** pagy 43.5.6.\n**Workaround (if you cannot upgrade):** validate the locale before\nassigning it, e.g.\n`Pagy::I18n.locale = params[:locale].to_s[/\\A[a-zA-Z]{2,8}(-[a-zA-Z0-9]{1,8})*\\z/]`,\nor restrict it to your known set of locales.","aliases":["CVE-2026-54659"],"modified":"2026-07-29T03:50:04.530742Z","published":"2026-07-28T22:25:29Z","database_specific":{"github_reviewed_at":"2026-07-28T22:25:29Z","nvd_published_at":null,"cwe_ids":["CWE-200","CWE-22"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc"},{"type":"WEB","url":"https://github.com/ddnexus/pagy/pull/908"},{"type":"WEB","url":"https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df"},{"type":"PACKAGE","url":"https://github.com/ddnexus/pagy"},{"type":"WEB","url":"https://github.com/ddnexus/pagy/releases/tag/43.5.6"}],"affected":[{"package":{"name":"pagy","ecosystem":"RubyGems","purl":"pkg:gem/pagy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"43.0.0"},{"fixed":"43.5.6"}]}],"versions":["43.0.0","43.0.1","43.0.2","43.0.3","43.0.4","43.0.5","43.0.6","43.0.7","43.1.0","43.1.1","43.1.2","43.1.3","43.1.4","43.1.5","43.1.6","43.1.7","43.1.8","43.2.0","43.2.1","43.2.10","43.2.2","43.2.3","43.2.4","43.2.5","43.2.6","43.2.7","43.2.8","43.2.9","43.3.0","43.3.1","43.3.2","43.3.3","43.4.0","43.4.1","43.4.2","43.4.3","43.4.4","43.5.0","43.5.1","43.5.2","43.5.3","43.5.4","43.5.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-2xmw-f8j8-wfxc/GHSA-2xmw-f8j8-wfxc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}