CVE Database
/

CVE-2026-34060

Back to search

CVE-2026-34060

Published: Mar 31, 2026

Modified: Apr 2, 2026

PUBLISHED

Description

Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace setting was interpolated without sanitization into a generated Gemfile, allowing arbitrary Ruby code execution when a user opens a project containing a malicious .vscode/settings.json. This issue has been patched in Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9.

VendorProductVersions

Shopify

ruby-lsp

affected
< 0.26.9

Shopify

Shopify.ruby-lsp

affected
< 0.10.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now