{"id":"GHSA-4g4c-8gqh-m4vm","summary":"paranoid2 gem Code backdoor","details":"The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.","aliases":["CVE-2019-13589"],"modified":"2026-03-13T22:11:53.350253Z","published":"2019-07-16T00:41:55Z","database_specific":{"github_reviewed_at":"2019-07-15T23:22:39Z","nvd_published_at":"2019-07-14T16:15:00Z","cwe_ids":["CWE-829"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13589"},{"type":"WEB","url":"https://github.com/rubygems/rubygems.org/issues/2051"},{"type":"PACKAGE","url":"https://github.com/anjlab/paranoid2"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/paranoid2/CVE-2019-13589.yml"},{"type":"WEB","url":"https://rubygems.org/gems/paranoid2/versions"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-RUBY-PARANOID2-451600"},{"type":"WEB","url":"http://www.securityfocus.com/bid/109281"}],"affected":[{"package":{"name":"paranoid2","ecosystem":"RubyGems","purl":"pkg:gem/paranoid2"},"versions":["1.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-4g4c-8gqh-m4vm/GHSA-4g4c-8gqh-m4vm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}