CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2011-10026

CVSS 9.3v4.0pub. 2025-08-20upd. 2025-11-25

Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables unauthenticated attackers to execute commands on the server.

🤖 AI Analysis
How it works

The vulnerability results from improper sanitization of the search[instance_eval] parameter passed to the API search function. The value of this parameter is dynamically invoked using Ruby's send method, which allows command injection and execution of arbitrary system shell commands. This mechanism requires no authentication, making the exploit available to any remote attacker.

Impact

An unauthenticated attacker can execute arbitrary system commands on the server hosting the application, which in practice means the possibility of complete server takeover, data theft, and further movement within the internal network (lateral movement).

Mitigation & patch

Spreecommerce Spree should be updated to version 0.50.x or newer. Detailed information about security patches is available in the vendor's announcement at the address indicated in the references (spreecommerce.com/blog/2011/04/19/security-fixes).

Who is affected

Spreecommerce Spree in all versions preceding 0.50.x

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Spreecommerce Spree

    APP
    Spreecommerce
    < 0.50.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassCommand Injection
CWE
References

Related vulnerabilities

CVE-2011-10019CRITICAL10.0PL ✓same product

RCE w Spreecommerce Spree — brak sanitizacji parametru wyszukiwania

CVE-2026-25758HIGH7.7same product

Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in ...

CVE-2026-25757HIGH7.7same product

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, ...

CVE-2026-22589HIGH7.5same product

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, ...

CVE-2020-26223HIGH7.7same product

Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and be...