numo-narray-alt is vulnerable to Code Injection
81
High Risk
The Numo::NArray.parse method converts a text representation of an array into an NArray. Each whitespace-delimited token in the input is passed to Ruby eval, so every token is executed as Ruby code. Parsing text that originates from a file, an upload, or a request parameter therefore runs arbitrary code in the host process. The fix parses each token only as a numeric or true/false/nil literal and rejects anything else.
You are affected if you are using a version that falls within the vulnerable range and your application passes untrusted text to Numo::NArray.parse.
numo-narray-alt is vulnerable to Code Injection in versions 0.9.3 - 0.10.6 and 0.11.0 - 0.11.1.
Upgrade the numo-narray-alt library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.