CRITICAL 9.8 RubyGems

paranoid2 gem Code backdoor

GHSA-4g4c-8gqh-m4vm · CVE-2019-13589

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.

Ready to move

Start Securing

Free, no credit card | First findings in minutes