Intel

AIKIDO-2025-10684

react-on-rails is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 9, 2025

80

High Risk

This Affects:

JSreact-on-rails
16.0.0 - 16.0.1
Fixed in 16.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper input validation, specifically in the generator package installation commands, where unsafe string interpolation allowed command injection. An attacker could exploit this by crafting malicious inputs, such as specially crafted package names or arguments, that bypass validation and execute arbitrary commands on the host system, potentially leading to unauthorized access or system compromise.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

react-on-rails is vulnerable to Improper Input Validation in versions 16.0.0 - 16.0.1.

How to fix this

Upgrade the react-on-rails library to the patch version.