Experts Discover Rack::Static Weakness Allowing Data Leaks in Ruby Servers
A team of cybersecurity experts has revealed three vulnerabilities in the Rack Ruby web server interface that, if exploited effectively, might allow intruders to obtain unauthorized entry to files, insert harmful data, and manipulate logs in specific scenarios.
The security holes, highlighted by cybersecurity firm OPSWAT, are outlined as follows –
The security holes, highlighted by cybersecurity firm OPSWAT, are outlined as follows –
CVE-2025-27610 (CVSS score: 7.5) – An instance of path traversal
