CVE-2026-34060
CRITICALRuby LSP has arbitrary code execution through branch setting
Title source: cnaDescription
Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace setting was interpolated without sanitization into a generated Gemfile, allowing arbitrary Ruby code execution when a user opens a project containing a malicious .vscode/settings.json. This issue has been patched in Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9.
Scores
CVSS v3
9.8
EPSS
0.0003
EPSS Percentile
7.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (3)
rubygems/ruby-lsp
0 - 0.26.9RubyGems
Shopify/ruby-lsp
< 0.26.9
Shopify/Shopify.ruby-lsp
< 0.10.2
Published
Mar 31, 2026
Tracked Since
Mar 31, 2026