CVE-2026-34060

Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace setting was interpolated without sanitization into a generated Gemfile, allowing arbitrary Ruby code execution when a user opens a project containing a malicious .vscode/settings.json. This issue has been patched in Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:shopify:ruby_lsp:*:*:*:*:*:visual_studio_code:*:*
cpe:2.3:a:shopify:ruby_lsp:*:*:*:*:*:ruby:*:*

History

No history.

Information

Published : 2026-03-31 03:15

Updated : 2026-06-17 10:38


NVD link : CVE-2026-34060

Mitre link : CVE-2026-34060

CVE.ORG link : CVE-2026-34060


JSON object : View

Products Affected

shopify

  • ruby_lsp
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')