CVE-2019-16255: Debian Linux
High severity, CVSS 8.1. EPSS: 4.2% chance of exploitation in the next 30 days.
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Opensuse Leap: version 15.1 only
- Oracle Graalvm: version 19.3.0.2 only
- Ruby-Lang Ruby: from 2.4.0, up to and including 2.4.7; from 2.5.0, up to and including 2.5.6; from 2.6.0, up to and including 2.6.4
Published 2019-11-26. Last modified 2026-06-17.