Back

CRITICAL

Spreecommerce < 0.60.2 Search Parameter RCE

Published Aug 13, 2025

Description

Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 13, 2025
Updated May 15, 2026
Reserved Aug 13, 2025
CISA Vulnrichment
Updated Aug 14, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-97VM-C39P-JR86