CVE-2019-3881: Bundler

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

Affected products

  • Bundler Bundler: before 2.1.0 (fixed in 2.1.0)

Published 2020-09-04. Last modified 2026-06-17.