Researchers Identify Rack::Static Vulnerability Enabling Data Breaches in Ruby Servers
Cybersecurity researchers have disclosed three security flaws in
the Rack Ruby web server interface that, if successfully exploited,
could enable attackers to gain unauthorized access to files, inject
malicious data, and tamper with logs under certain conditions. The
vulnerabilities, flagged by cybersecurity vendor OPSWAT, are listed
below - CVE-2025-27610 (CVSS score: 7.5) - A path traversal
Read more https://thehackernews.com/2025/04/researchers-identify-rackstatic.html