image_processing is vulnerable to Remote Code Execution (RCE)
93
Critical Risk
Operation and MiniMagick loader/saver option names taken from caller input are dispatched to the underlying image library without fully checking whether the name resolves to an unsafe Ruby core method. A crafted name can invoke methods such as eval, send, or instance_eval, so an attacker who controls those names can execute arbitrary Ruby code or shell commands on the server. The fix validates every operation and loader/saver option name at the point it is dispatched, closing bypasses that slipped past the outer-level checks.
You are affected if you are using a version that falls within the vulnerable range and build image_processing operations or MiniMagick loader/saver options from untrusted input.
image_processing is vulnerable to Remote Code Execution (RCE) in versions 0.10.0 - 2.0.2.
Upgrade the image_processing library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant