-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| publify_core | rubygems | < 9.2.9 | 9.2.9 |
The vulnerability stems from the pre-patch implementation where:
The commit fixes this by strictly using params[:id] for both authorization and article lookup, and the added test case explicitly verifies protection against article[id] parameter manipulation.
A Semantic Attack on Google Gemini - Read the Latest Research