PT-2025-34107 · Unknown · Spree Commerce

Published

2025-08-20

·

Updated

2025-08-20

·

CVE-2011-10026

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spreecommerce versions prior to 0.50.x
Description The software contains a remote command execution issue in the API’s search functionality. Insufficient input validation allows attackers to inject arbitrary shell commands through the search[instance eval] parameter. This parameter is dynamically invoked using Ruby’s send method. This allows unauthenticated attackers to execute commands on the server.
Recommendations Update to version 0.50.x or later.

Exploit

Fix

Code Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2011-10026
GHSA-X485-RHG3-CQR4

Affected Products

Spree Commerce