CVE-2025-61772: Unescaped Regex Path Prefix

Detected unescaped variable interpolation within a regular expression used for path/prefix substitution. If the variable contains regular expression metacharacters, the substitution can match unintended segments of the target string. In the context of directory paths, this can lead to absolute path disclosure or incorrect logic. Use `Regexp.escape()` or `Reg

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Ruby
greprules fetch cve-2025-61772-unescaped-regex-path-prefix --engine opengrep

Description

Detected unescaped variable interpolation within a regular expression used for path/prefix substitution. If the variable contains regular expression metacharacters, the substitution can match unintended segments of the target string. In the context of directory paths, this can lead to absolute path disclosure or incorrect logic. Use `Regexp.escape()` or `Reg