CRITICAL 9.8 RubyGems

Code injection in pdf_info

GHSA-9fh3-j99m-f4v7 · CVE-2022-36231

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

pdf_info 0.5.3 is vulnerable to Command Execution. An attacker using a specially crafted payload may execute OS commands by using command chaining because during object initalization there is no validation performed and the user provided path is used.

Ready to move

Start Securing

Free, no credit card | First findings in minutes