The Square Squash allows remote attackers to execute...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Description
Published by the National Vulnerability Database
May 27, 2014
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Apr 12, 2025
The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb.
References