Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-5250 | Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server. |
Github GHSA |
GHSA-x485-rhg3-cqr4 | Spree Commerce is vulnerable to RCE through Search API |
Tue, 25 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Wed, 24 Sep 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spreecommerce
Spreecommerce spree |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Spreecommerce
Spreecommerce spree |
|
| Metrics |
cvssV3_1
|
Wed, 20 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server. | |
| Title | Spreecommerce < 0.50.x API RCE | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T11:13:45.921Z
Reserved: 2025-08-18T20:39:27.409Z
Link: CVE-2011-10026
Updated: 2025-08-20T18:11:48.355Z
Status : Modified
Published: 2025-08-20T16:15:35.440
Modified: 2025-11-25T15:15:47.310
Link: CVE-2011-10026
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA