Arbitrary method invocation turbo_boost-commands
Published Mar 14, 2024
8.1
HIGHCVSS 3.1
EPSS 0.80%
Description
turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. Commands verify that the class must be a `Command` and that the method requested is defined as a public method; however, this isn't robust enough to guard against all unwanted code execution. The library should more strictly enforce which methods are considered safe before allowing them to be executed. This issue has been addressed in versions 0.1.3, and 0.2.2. Users are advised to upgrade. Users unable to upgrade should see the repository GHSA for workaround advice.
Affected products
-
- Version < 0.1.3StatusaffectedConstraints-
- Version >= 0.2.0, < 0.2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hopsoft | Turbo Boost-Commands | n/a |
|
- < 0.1.3
- ≥ 0.2.0 · < 0.2.2
-
- Version 0StatusaffectedConstraints<0.1.3
- Version 0.2.0StatusaffectedConstraints<0.2.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hopsoft | Turboboost Commands | n/a |
|
No Red Hat product state for this CVE.
turbo_boost-commands
RubyGems
Introduced 0 Fixed 0.1.3turbo_boost-commands
RubyGems
Introduced 0.2.0 Fixed 0.2.2@turbo-boost/commands
npm
Introduced 0 Fixed 0.1.3@turbo-boost/commands
npm
Introduced 0.2.0 Fixed 0.2.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| RubyGems | turbo_boost-commands | 0 | 0.1.3 |
| RubyGems | turbo_boost-commands | 0.2.0 | 0.2.2 |
| npm | @turbo-boost/commands | 0 | 0.1.3 |
| npm | @turbo-boost/commands | 0.2.0 | 0.2.2 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jul 19, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.80% (0.00796) | 54.84th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.80% (0.00796) | 51.47th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.24% (0.00245) | 47.66th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.68% (0.01683) | 80.69th | v4 (v2025.03.14) |
| Apr 22, 2025 | 0.10% (0.00100) | 28.91th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.56% (0.01564) | 79.79th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.41% (0.05414) | 83.20th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.24% (0.01239) | 77.86th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00043) | 10.81th | v3 (v2023.03.01) |
| Jul 10, 2024 | 0.04% (0.00043) | 9.24th | v3 (v2023.03.01) |
| Mar 15, 2024 | 0.04% (0.00043) | 7.19th | v3 (v2023.03.01) |
References (6)
- https://github.com/advisories/GHSA-mp76-7w5v-pr75 Advisory
- https://github.com/hopsoft/turbo_boost-commands/commit/337cda7d9222f1f449905454a7374222017a7477
- https://github.com/hopsoft/turbo_boost-commands/commit/88af4fc0ac39cc1799d16c49fab52f6dfbcec9ba x_refsource_MISCPatch
- https://github.com/hopsoft/turbo_boost-commands/security/advisories/GHSA-mp76-7w5v-pr75 x_refsource_CONFIRMVendor Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/turbo_boost-commands/CVE-2024-28181.yml
- https://nvd.nist.gov/vuln/detail/CVE-2024-28181
Change history (0)
No recorded changes yet.