CVE-2019-10780: Bibtex-Ruby Project Bibtex-Ruby

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open.

Affected products

Published 2020-01-22. Last modified 2026-06-17.