CVE-2023-26153: Geokit Geokit-Rails
Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.
Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to execute commands on the host system.
Affected products
- Geokit Geokit-Rails: before 2.5.0 (fixed in 2.5.0)
Published 2023-10-06. Last modified 2026-06-17.