Intel

AIKIDO-2025-10396

solid_cable is vulnerable to Race Condition

Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 23, 2025

45

Medium Risk

This Affects:

Rubysolid_cable
0.1.0 - 3.0.10
Fixed in 3.0.11
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to race conditions and message replay attacks, where a reconnecting client may receive duplicate or outdated messages due to improper tracking of the last processed message ID. An attacker could exploit this by forcing clients to disconnect and reconnect, causing them to reprocess old messages, potentially exposing sensitive system information or exhausting resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

solid_cable is vulnerable to Race Condition in versions 0.1.0 - 3.0.10.

How to fix this

Upgrade the solid_cable library to the patch version.