VYPR
High severity7.8NVD Advisory· Published Jul 12, 2019· Updated Jun 17, 2026

CVE-2019-13574

CVE-2019-13574

Description

In lib/mini_magick/image.rb in MiniMagick before 4.9.4, a fetched remote image filename could cause remote command execution because Image.open input is directly passed to Kernel#open, which accepts a '|' character followed by a command.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mini_magickRubyGems
< 4.9.44.9.4

Affected products

5
  • cpe:2.3:a:minimagick_project:minimagick:*:*:*:*:*:*:*:*
    Range: <4.9.4
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • MiniMagick/MiniMagickdescription
  • ghsa-coords
    Range: < 4.9.4

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.