CVE-2013-4457: Thoughtbot Cocaine
Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.
The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.
Affected products
- Thoughtbot Cocaine: version 0.4.0 only; version 0.4.1 only; version 0.4.2 only; version 0.5.0 only; version 0.5.1 only; version 0.5.2 only
Published 2013-11-02. Last modified 2026-06-16.