GHSA-7wqh-767x-r66v
Local File Inclusion in Rack::Static
Quick fix
GHSA-7wqh-767x-r66v — rack: upgrade to the fixed version with the command below.
bundle update rackDetails
## Summary
`Rack::Static` can serve files under the specified `root:` even if `urls:` are provided, which may expose other files under the specified `root:` unexpectedly.
## Details
The vulnerability occurs because `Rack::Static` does not properly sanitize user-supplied paths before serving files. Specifically, encoded path traversal sequences are not correctly validated, allowing attackers to access files outside the designated static file directory.
## Impact
By exploiting this vulnerability, an attacker can gain access to all files under the specified `root:` directory, provided they are able to determine then path of the file.
## Mitigation
- Update to the latest version of Rack, or - Remove usage of `Rack::Static`, or - Ensure that `root:` points at a directory path which only contains files which should be accessed publicly.
It is likely that a CDN or similar static file server would also mitigate the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rack/rack/security/advisories/GHSA-7wqh-767x-r66v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-27610[ADVISORY]
- https://github.com/rack/rack/commit/50caab74fa01ee8f5dbdee7bb2782126d20c6583[WEB]
- https://github.com/rack/rack[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2025-27610.yml[WEB]
- https://lists.debian.org/debian-lts-announce/2025/03/msg00016.html[WEB]