spoom is vulnerable to OS Command Injection
78
High Risk
Spoom::Context::Git builds git commands by interpolating refs and branch names directly into a shell string in git_checkout!, git_init!, and git_checkout_new_branch!. Git ref naming rules forbid spaces but allow ;, $, backticks, and other shell metacharacters, so a branch name such as main;touch${IFS}pwned runs as a sibling shell command once passed to /bin/sh. spoom srb coverage timeline reads and replays branch and commit refs from the analyzed repository through this path, and any consumer of the public Context API passing repository-derived refs is affected the same way. The fix escapes every interpolated ref and branch argument with shellescape.
You are affected if you are using a version that falls within the vulnerable range and you run spoom srb coverage timeline, or otherwise pass repository-derived git refs or branch names to Spoom::Context::Git, against an untrusted repository.
spoom is vulnerable to OS Command Injection in versions 1.0.5 - 1.8.8.
Upgrade the spoom library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.