CVE-2014-9489: Gollum Project Gollum
High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the -O or --open-files-in-pager flags.
Affected products
- Gollum Project Gollum: up to and including 3.1.0
- Gollum Project Gollum-Lib: up to and including 4.0.0
- Gollum Project Grit Adapter: up to and including 0.1.0
Published 2017-10-17. Last modified 2026-06-17.