VDB
Sign up
HIGH7.8

GHSA-r7j3-vvh2-xrpj

OS Command Injection in MiniMagick

Quick fix

GHSA-r7j3-vvh2-xrpj — mini_magick: upgrade to the fixed version with the command below.

bundle update mini_magick

Details

In `lib/mini_magick/image.rb` in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because `Image.open` input is directly passed to `Kernel#open`, which accepts a `|` character followed by a command.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/mini_magick
Introduced in: 0Fixed in: 4.9.4
Fixbundle update mini_magick

References