Executive brief
Spree Commerce is vulnerable to RCE through Search API
Affected products
- RubyGems spree
- RubyGems rd_searchlogic
Junglewise Threat Intelligence
CVE-2011-10026 · Severity: medium · CVSS 4 · Published 2025-08-20
Technologies: spree (RubyGems). Vendors: RubyGems.
Spree Commerce is vulnerable to RCE through Search API