{"id":"GHSA-9hx9-w2j6-rw76","summary":"Script Injection in Show In Browser gem","details":"The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on `/tmp/browser.html`.","aliases":["CVE-2013-2105"],"modified":"2025-04-13T23:26:43Z","published":"2017-10-24T18:33:37Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:28:50Z","nvd_published_at":"2014-04-22T14:23:33Z","cwe_ids":["CWE-59"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2105"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/84378"},{"type":"PACKAGE","url":"https://github.com/jonleung/show_in_browser"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/show_in_browser/CVE-2013-2105.yml"},{"type":"WEB","url":"http://vapid.dhs.org/advisories/show_in_browser.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/05/18/4"}],"affected":[{"package":{"name":"show_in_browser","ecosystem":"RubyGems","purl":"pkg:gem/show_in_browser"},"versions":["0.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-9hx9-w2j6-rw76/GHSA-9hx9-w2j6-rw76.json"}}],"schema_version":"1.9.0"}