Critical severityNVD Advisory· Published Apr 25, 2013· Updated Jun 16, 2026
CVE-2013-1948
CVE-2013-1948
Description
converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
md2pdfRubyGems | <= 0.0.1 | — |
Affected products
2- cpe:2.3:a:rob_westgeest:md2pdf:0.0.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-99ch-8mvp-g7m5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-1948ghsaADVISORY
- vapid.dhs.org/advisories/md2pdf-remote-exec.htmlnvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/83416nvdWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/md2pdf/CVE-2013-1948.ymlghsaWEB
- web.archive.org/web/20130503194109/http://www.securityfocus.com/bid/59061ghsaWEB
- osvdb.org/92290nvd
- www.securityfocus.com/bid/59061nvd
News mentions
0No linked articles in our index yet.