CVE-2026-34060
Severity CVSS v4.0:
HIGH
Type:
CWE-94
Code Injection
Publication date:
31/03/2026
Last modified:
02/04/2026
Description
Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9, the rubyLsp.branch VS Code workspace setting was interpolated without sanitization into a generated Gemfile, allowing arbitrary Ruby code execution when a user opens a project containing a malicious .vscode/settings.json. This issue has been patched in Shopify.ruby-lsp version 0.10.2 and ruby-lsp version 0.26.9.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL



