spoom is vulnerable to OS Command Injection
78
High Risk
Spoom::FileCollector#mime_type_for shells out to the file command by interpolating a scanned file's path into a single-quoted shell string. A file name that contains a single quote breaks out of that quoting, letting a crafted file name in the analyzed repository run arbitrary OS commands during the default spoom deadcode scan. The path reaching this call is normalized with cleanpath but never shell-escaped before use. The fix replaces the shell interpolation with Open3.capture2, passing the path as a separate process argument instead of through /bin/sh.
You are affected if you are using a version that falls within the vulnerable range and you run spoom deadcode over a repository containing files with untrusted names.
spoom is vulnerable to OS Command Injection in versions 1.2.2 - 1.8.8.
Upgrade the spoom library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.