CVE-2026-67986: Code Injection
amazing-print/amazingprint at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67986?
CVE-2026-67986 has a risk rating of 59, indicating a moderate severity level.
How does CVE-2026-67986 affect amazing-print?
CVE-2026-67986 allows code injection through a specially named method and Ruby interpolation, posing a security risk.
How do I fix CVE-2026-67986?
Updating to the latest version of amazing-print that addresses the code injection vulnerability is recommended to fix CVE-2026-67986.
When was CVE-2026-67986 published?
CVE-2026-67986 was published on August 13, 2026.
What type of vulnerability is CVE-2026-67986 categorized as?
CVE-2026-67986 is categorized as a Code Injection vulnerability.