RubySec

Providing security resources for the Ruby community

CVE-2025-54314 (thor): Thor can construct an unsafe shell command from library input.

Thor can construct an unsafe shell command from library input.

Published: July 20, 2025

SECURITY IDENTIFIERS

GEM

thor

SEVERITY

CVSS v3.x: 2.8 (Low)

PATCHED VERSIONS

>= 1.4.0

DESCRIPTION

Thor before 1.4.0 can construct an unsafe shell command from library input.

RELATED