CVE-2014-9489: Gollum Project Gollum

High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.

The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the -O or --open-files-in-pager flags.

Affected products

Published 2017-10-17. Last modified 2026-06-17.