THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mx5j-mp4f-g8jg (high) — Savon::Model evaluates WSDL operation names as Ruby source

[GHSA] GHSA-mx5j-mp4f-g8jg (high) — Savon::Model evaluates WSDL operation names as Ruby source

medgithub_advisoriesPublished 2026-07-31

GHSA-mx5j-mp4f-g8jg Severity: high CVE: CVE-2026-53510

Savon::Model evaluates WSDL operation names as Ruby source

### Impact

`Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the `.all

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mx5j-mp4f-g8jg