ruby-lsp
An opinionated language server for Ruby
Activity
- Latest release
- 3w ago
- Total releases
- 155
- Cadence
- ~6 days
- Last 12 months
- 15
Reach
- Downloads
- 35.9M
- Stars
- 2.0k
Details
- License
- MIT
- First release
- Mar 01, 2022
| Version | Released | |
|---|---|---|
0.27.0.beta5
pre
| ||
0.26.11
patch
| ||
0.26.10
patch
| ||
0.27.0.beta4
pre
| ||
0.27.0.beta3
pre
| ||
0.27.0.beta2
pre
| ||
0.27.0.beta1
pre
| ||
0.26.9
patch
| ||
0.26.8
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.26.7
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.26.6
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.26.5
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.26.4
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.26.3
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.26.2
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.26.1
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.26.0
minor
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.25.0
minor
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.24.2
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.24.1
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.24.0
minor
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.24
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.23
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.22
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.21
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.20
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.19
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.18
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.17
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.16
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.15
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.14
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.13
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.12
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.11
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.10
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.9
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.8
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.7
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.6
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.4
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.5
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.3
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.2
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.1
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.23.0
minor
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.22.1
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.22.0
minor
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.21.3
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev | ||
0.21.2
patch
1 CVE
CVE-2026-34060
GHSA-c4r5-fxqw-vh93
Mar 27, 2026
Ruby LSP has arbitrary code execution through branch setting
High
Local
Low
None
Summary The Other editors that support workspace setting that get automatically applied upon opening the editor and trusting the workspace are also impacted since the server is the component that performs the interpolation. Details The Impact Code execution with the privileges of the user who opens the malicious project. Ruby LSP assumes workspace code is trusted and so opening the editor on an untrusted workspace can lead to executing potentially dangerous code. Remediation The The Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.12.0
0.12.1
+ 135 more Show less
0.12.2
0.12.3
0.12.4
0.12.5
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0
0.14.1
0.14.2
0.14.3
0.14.4
0.14.5
0.14.6
0.15.0
0.16.0
0.16.1
0.16.2
0.16.3
0.16.4
0.16.5
0.16.6
0.16.7
0.17.0
0.17.1
0.17.10
0.17.11
0.17.12
0.17.13
0.17.14
0.17.15
0.17.16
0.17.17
0.17.2
0.17.3
0.17.4
0.17.5
0.17.6
0.17.7
0.17.8
0.17.9
0.18.0
0.18.1
0.18.2
0.18.3
0.18.4
0.19.0
0.19.1
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.20.0
0.20.1
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.23.0
0.23.1
0.23.10
0.23.11
0.23.12
0.23.13
0.23.14
0.23.15
0.23.16
0.23.17
0.23.18
0.23.19
0.23.2
0.23.20
0.23.21
0.23.22
0.23.23
0.23.24
0.23.3
0.23.4
0.23.5
0.23.6
0.23.7
0.23.8
0.23.9
0.24.0
0.24.1
0.24.2
0.25.0
0.26.0
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.26.6
0.26.7
0.26.8
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.5.0
0.5.1
0.6.0
0.6.1
0.6.2
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
0.9.4
Fixed in
0.26.9
References
Updated Mar 31, 2026 · Source: OSV.dev |