A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. This vulnerability appears in code generated by the Rexical gem versions v1.0.6 and earlier. Rexical is used by Nokogiri to generate lexical scanner code for parsing CSS queries. The underlying vulnerability was addressed in Rexical v1.0.7 and Nokogiri upgraded to this version of Rexical in Nokogiri v1.10.4.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ruby-nokogiri | Aug 22, 2024 | Aug 16, 2019 |
| Debian | — | Upgrade ruby-nokogiriUpgrade rexical | Sep 27, 2019 | Aug 16, 2019 |
| Freebsd | — | Upgrade rubygem-nokogiri | Aug 14, 2019 | Aug 13, 2019 |
| Gentoo Linux | — | Upgrade dev-ruby/nokogiri. | Jun 15, 2020 | Aug 16, 2019 |
| Suse | — | Upgrade ruby2.5-rubygem-nokogiriUpgrade ruby2.5-rubygem-nokogiri-testsuiteUpgrade ruby2.5-rubygem-nokogiri-doc | Feb 6, 2021 | Aug 11, 2019 |
| Ubuntu | — | Upgrade ruby-nokogiri | Nov 6, 2019 | Aug 11, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 16, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub