{"id":"UBUNTU-CVE-2025-54314","details":"Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because \"the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments.\"","modified":"2026-05-20T16:23:36.146952026Z","published":"2025-07-20T03:15:00Z","upstream":["CVE-2025-54314"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-54314"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-54314"},{"type":"REPORT","url":"https://hackerone.com/reports/3260153"},{"type":"REPORT","url":"https://github.com/rails/thor/pull/897"},{"type":"REPORT","url":"https://github.com/rails/thor/commit/536b79036a0efb765c1899233412e7b1ca94abfa"},{"type":"REPORT","url":"https://github.com/rails/thor/releases/tag/v1.4.0"}],"affected":[{"package":{"name":"ruby-thor","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/ruby-thor?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.18.1-1","0.18.1.git20140116-2"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-thor","binary_version":"0.18.1.git20140116-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54314.json"}},{"package":{"name":"ruby-thor","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/ruby-thor?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.19.1-2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.19.1-2","binary_name":"ruby-thor"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54314.json"}},{"package":{"name":"ruby-thor","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/ruby-thor?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.19.4-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-thor","binary_version":"0.19.4-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54314.json"}},{"package":{"name":"ruby-thor","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/ruby-thor?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.19.4-1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-thor","binary_version":"0.19.4-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54314.json"}},{"package":{"name":"ruby-thor","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ruby-thor?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.1-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.0.1-1","binary_name":"ruby-thor"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54314.json"}},{"package":{"name":"ruby-thor","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ruby-thor?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.1-2","1.2.2-1","1.3.1-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.1-1","binary_name":"ruby-thor"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54314.json"}},{"package":{"name":"ruby-thor","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/ruby-thor?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.2-2","1.3.2-2.1"],"ecosystem_specific":{"binaries":[{"binary_name":"ruby-thor","binary_version":"1.3.2-2.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54314.json"}},{"package":{"name":"ruby-thor","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/ruby-thor?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.2-2.1","1.4.0-1","1.5.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.5.0-1","binary_name":"ruby-thor"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-54314.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}