-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| publify_core | rubygems | < 9.2.10 | 9.2.10 |
The vulnerability stems from Publify Core's failure to strip EXIF metadata from uploaded images. The patch introduced two new CarrierWave processes (strip and fix_exif_rotation) in ResourceUploader to address this. In vulnerable versions (<9.2.10), these processes were absent, leaving the system's image processing pipeline incomplete and allowing insecure storage of sensitive metadata. The primary vulnerable component is the image processing workflow in ResourceUploader, which lacked critical sanitization steps.
Ongoing coverage of React2Shell