CVE-2019-10780: Bibtex-Ruby Project Bibtex-Ruby
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open.
Affected products
- Bibtex-Ruby Project Bibtex-Ruby: before 5.1.0 (fixed in 5.1.0)
Published 2020-01-22. Last modified 2026-06-17.