CVE-2013-7086: Webbynode

High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.

The message function in lib/webbynode/notify.rb in the Webbynode gem 1.0.5.3 and earlier for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a growlnotify message.

Affected products

  • Webbynode Webbynode: up to and including 1.0.5.3; version 1.0.5 only; version 1.0.5.1 only; version 1.0.5.2 only

Published 2013-12-19. Last modified 2026-06-17.