Intel

AIKIDO-2026-482004

spoom is vulnerable to OS Command Injection

OS Command InjectionGHSA-f377-gfmr-h7r7 Published Yesterday

78

High Risk

This Affects:

RUBYspoom
1.2.2 - 1.8.8
Fixed in 1.8.9
Are you affected? Scan for Free

TL;DR

Spoom::FileCollector#mime_type_for shells out to the file command by interpolating a scanned file's path into a single-quoted shell string. A file name that contains a single quote breaks out of that quoting, letting a crafted file name in the analyzed repository run arbitrary OS commands during the default spoom deadcode scan. The path reaching this call is normalized with cleanpath but never shell-escaped before use. The fix replaces the shell interpolation with Open3.capture2, passing the path as a separate process argument instead of through /bin/sh.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run spoom deadcode over a repository containing files with untrusted names.

Background info

spoom is vulnerable to OS Command Injection in versions 1.2.2 - 1.8.8.

How to fix this

Upgrade the spoom library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform