Pagy Gem I18n Locale Option Vulnerability: Early Warning
An early warning has been issued regarding a potential vulnerability in the Pagy gem's I18n locale option, which reportedly allows untrusted input to influence file paths.
What happened
The Pagy gem's I18n locale option is under investigation for a vulnerability where the locale is not validated before being used in a file path. This could potentially allow untrusted input to redirect the lookup outside the locales directory.
To assess your exposure, check if your application uses the Pagy gem with a version lower than 43.5.6. If so, it is recommended to upgrade to version 43.5.6 or later to mitigate the vulnerability.
For more detailed information, consult the primary source at [GHSA-2xmw-f8j8-wfxc](https://github.com/ddnexus/pagy/security/advisories/GHSA-2xmw-f8j8-wfxc).
How 0Day mitigates this
pagy is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.