VDB

GCVE-110-GEM-2026-000930

GCVE-110-GEM-2026-000930
Advisory Published
Vulnetix · Advisory published October 3, 2026
The RubyGems gem `specinfra` (version 2.95.2) was flagged as malicious by automated package analysis (7 corroborating detection(s)). Installing it may execute attacker-controlled code via the gemspec's native `extensions` build, install hooks, or bundled Ruby/C sources. Verdict path: evidence — for ownership-only paths (owner-known-bad / multi-identity) the change of ownership is a compounding indicator the engine correlated with other signals, not standalone proof. This verdict is produced by static analysis and is subject to human review.

Weaknesses (CWE)

CWE-506Embedded Malicious CodeCWE-522Insufficiently Protected CredentialsCWE-200Exposure of Sensitive Information to an Unauthorized Actor

Affected Products

VendorProductVersionsPlatforms
rubygemsspecinfra2.95.2 (affected)—

References

advisory
web

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›