CVE-2019-17268: Omniauth-Weibo-OAUTH2 Project Omniauth-Weibo-OAUTH2

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.

Affected products

Published 2020-02-07. Last modified 2026-06-17.