HIGH 7.8 RubyGems

Withdrawn Advisory: Thor can construct an unsafe shell command from library input.

GHSA-mqcp-p2hv-vw6x · CVE-2025-54314

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Withdrawn Advisory

This advisory has been withdrawn because the method described can only be used with arguments that are controlled by Thor, and an external attacker cannot access the functionality described in the body of the CVE. This link is maintained to preserve external references.

Original Description

Thor before 1.4.0 can construct an unsafe shell command from library input.

Ready to move

Start Securing

Free, no credit card | First findings in minutes