CVE-2026-34763: Ruby Unescaped Regex Stripping

An unescaped string is interpolated into a regular expression and used to strip content from a string using `.sub` or `.gsub`. If the variable contains regex metacharacters, the match may fail or behave unexpectedly. This can lead to information disclosure, such as exposing absolute internal paths. Use `Regexp.escape()` or `Regexp.quote()` to safely interpol

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Ruby
greprules fetch cve-2026-34763-ruby-unescaped-regex-stripping --engine opengrep

Description

An unescaped string is interpolated into a regular expression and used to strip content from a string using `.sub` or `.gsub`. If the variable contains regex metacharacters, the match may fail or behave unexpectedly. This can lead to information disclosure, such as exposing absolute internal paths. Use `Regexp.escape()` or `Regexp.quote()` to safely interpol