What is CVE-2026-48122?
CVE-2026-48122 affects the Ruby LSP VS Code extension prior to version 0.10.4. A malicious workspace configuration can override the paths for the Ruby executable, version manager, or Bundler `Gemfile`, potentially leading to arbitrary code execution when the workspace is opened. Users must upgrade to version 0.10.4 or later immediately and exercise caution with untrusted repositories.
Azərbaycanca: CVE-2026-48122, Ruby LSP VS Code genişləndirilməsinin 0.10.4-dən əvvəlki versiyalarında aşkarlanmışdır. Bu boşluq zərərli layihə faylları vasitəsilə Ruby, versiya meneceri və ya Bundler `Gemfile` icra olunan fayllarının yolunu dəyişməyə imkan verərək, iş mühitində ixtiyari kod icrasına səbəb ola bilər. İstifadəçilər təcili olaraq 0.10.4 və ya daha yeni versiyaya yeniləmə etməli, etibar edilməyən kod bazaları ilə işləyərkən diqqətli olmalıdırlar.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What version of the Ruby LSP VS Code extension is affected by CVE-2026-48122?
Versions of the Ruby LSP VS Code extension prior to 0.10.4 are affected. Users must immediately upgrade to version 0.10.4 or later to remediate the vulnerability.
How can users protect themselves from CVE-2026-48122?
Users must upgrade the Ruby LSP VS Code extension to version 0.10.4 or later immediately and exercise caution when working with untrusted repositories.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.