CVE-2019-13589: Anjlab PARANOID2

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.

Affected products

  • Anjlab PARANOID2: version 1.1.6 only

Published 2019-07-14. Last modified 2026-06-17.