Intel

AIKIDO-2026-809403

spoom is vulnerable to OS Command Injection

OS Command InjectionGHSA-5wj6-43r5-jqw3 Published Yesterday

78

High Risk

This Affects:

RUBYspoom
1.0.5 - 1.8.8
Fixed in 1.8.9
Are you affected? Scan for Free

TL;DR

Spoom::Context::Git builds git commands by interpolating refs and branch names directly into a shell string in git_checkout!, git_init!, and git_checkout_new_branch!. Git ref naming rules forbid spaces but allow ;, $, backticks, and other shell metacharacters, so a branch name such as main;touch${IFS}pwned runs as a sibling shell command once passed to /bin/sh. spoom srb coverage timeline reads and replays branch and commit refs from the analyzed repository through this path, and any consumer of the public Context API passing repository-derived refs is affected the same way. The fix escapes every interpolated ref and branch argument with shellescape.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run spoom srb coverage timeline, or otherwise pass repository-derived git refs or branch names to Spoom::Context::Git, against an untrusted repository.

Background info

spoom is vulnerable to OS Command Injection in versions 1.0.5 - 1.8.8.

How to fix this

Upgrade the spoom library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform