← Daily
πŸ“ article base16.fr · August 26, 2026

How I found two command injections in the spatial_features Ruby gem

A walkthrough of finding two command injection paths in the spatial_features gem, where filenames reached system() unsanitised. Fixed in 3.11.2, and a good read on how to spot the pattern in your own dependencies.

While using the spatial_features Ruby gem for a side project, I noticed that filenames were being passed to system. It led me to two command injection paths, fixed in version 3.11.2. Here’s how I found them, built the PoC, and reported the issue: https://base16.fr/en/blog/command-injection-spatial-features

Read on base16.fr →

More from this day

+ Feature your site