π
article
base16.fr
·
August 26, 2026
How I found two command injections in the spatial_features Ruby gem
A walkthrough of finding two command injection paths in the spatial_features gem, where filenames reached system() unsanitised. Fixed in 3.11.2, and a good read on how to spot the pattern in your own dependencies.
While using the spatial_features Ruby gem for a side project, I noticed that filenames were being passed to system. It led me to two command injection paths, fixed in version 3.11.2. Hereβs how I found them, built the PoC, and reported the issue: https://base16.fr/en/blog/command-injection-spatial-features
Read on base16.fr →