CVE-2015-3649: Open-Uri-Cached Project Open-Uri-Cached

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a crafted UID, and putting Ruby code in said directory once a meta file is created.

Affected products

Published 2017-08-18. Last modified 2026-06-17.