{"id":"CVE-2026-54659","aliases":["GHSA-2xmw-f8j8-wfxc"],"title":"Pagy I18n locale option is not validated before being used in a file path","summary":"Pagy I18n locale option is not validated before being used in a file path","severity":"medium","cwe":["CWE-22","CWE-200"],"vendor":"pagy","product":"pagy","ecosystem":"rubygems","affected":["pagy >= 43.0.0, < 43.5.6"],"patched":["pagy 43.5.6"],"published":"2026-07-28","updated":"2026-07-28","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-2xmw-f8j8-wfxc","references":[{"url":"https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc"},{"url":"https://github.com/ddnexus/pagy/pull/908"},{"url":"https://github.com/ddnexus/pagy/commit/efcf09690e9fa7d7abdfb987b785a55f87e287df"},{"url":"https://github.com/ddnexus/pagy/releases/tag/43.5.6"},{"url":"https://github.com/advisories/GHSA-2xmw-f8j8-wfxc"}],"tags":["ghsa","rubygems"],"ingestedAt":"2026-07-28T22:40:03.087Z","epss":0.0054,"epssPercentile":0.42961,"slug":"CVE-2026-54659","body":"## Overview\n\n### Summary\n\n`Pagy::I18n.locale=` did not validate its argument before using it as a\npath component to load the matching dictionary file (`<locale>.yml`). An\napplication that assigns untrusted input to the locale — e.g. the common\npattern `Pagy::I18n.locale = params[:locale]` — let that input influence\nwhich file Pagy attempted to load.\n\n### Details\n\nThe setter stored the value as-is, and the loader joined it into a path\nand read it:\n\n```ruby\n# gem/lib/pagy/modules/i18n/i18n.rb\ndef locale=(value)\n  Thread.current[:pagy_locale] = value.to_s\nend\n\n# ...later, when translating:\npath = pathnames.reverse.map { |p| p.join(\"#{locale}.yml\") }.find(&:exist?)\ndictionary = YAML.load_file(path)[locale]\n```\n\nBecause the locale was used verbatim, a value such as an absolute path or\na `../`-style string redirected the lookup outside the locales directory.\nPagy's subsequent structural check (`dictionary['pagy']['p11n']`)\nprevents the file's contents from being returned, so this is **not** a\ndirect file read.\n\nFixed in 43.5.6 by constraining the locale to a BCP 47 shape before use:\n\n```ruby\nLOCALE_PATTERN = /\\A[a-zA-Z]{2,8}(-[a-zA-Z0-9]{1,8})*\\z/\n\ndef locale=(value)\n  Thread.current[:pagy_locale] = value.to_s[LOCALE_PATTERN]\nend\n```\n\nAny non-matching value (including `nil`) resolves to the default locale\nand never reaches the file lookup.\n\n### PoC\n\nIn an application that sets `Pagy::I18n.locale = params[:locale]`, the\nloader appends `.yml` and reads `<locale>.yml`, so the request param\ncontrols the target path. For example, pointing it at the app's\n`config/database.yml`:\n\n1. Send a request with `?locale=../../../config/database` (adjust the\n   number of `../` to reach the app root from the gem's `locales/`\n   directory).\n2. Pagy calls `YAML.load_file` on the resulting `…/config/database.yml`.\n3. The outcome differs by whether that `.yml` exists, is readable, parses\n   as YAML, and has Pagy's expected structure — an existing, readable\n   `config/database.yml` raises a different error than a non-existent\n   path (which silently falls back to the default locale). This yields a\n   file-existence / readability oracle for `.yml` paths, and the targeted\n   file is read into the process during the attempt.\n\n### Impact\n\nInformation disclosure (CWE-22 / CWE-200): a file-existence / readability\noracle for `.yml` paths on the host, plus a server-side read of\nattacker-chosen files into the process. The file contents are not\nreturned in the response.\n\nOnly applications that pass **unsanitized end-user input** into\n`Pagy::I18n.locale=` are affected. Applications that set the locale from\ntrusted values are not affected.\n\n**Patched:** pagy 43.5.6.\n**Workaround (if you cannot upgrade):** validate the locale before\nassigning it, e.g.\n`Pagy::I18n.locale = params[:locale].to_s[/\\A[a-zA-Z]{2,8}(-[a-zA-Z0-9]{1,8})*\\z/]`,\nor restrict it to your known set of locales.\n\n## Affected packages\n\n- `pagy >= 43.0.0, < 43.5.6`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pagy 43.5.6`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}