CVE-2021-35514
Ruby vulnerability analysis and mitigation

Overview

Narou (aka Narou.rb) before version 3.8.0 contains a Ruby Code Injection vulnerability (CVE-2021-35514) that was discovered and disclosed on June 28, 2021. The vulnerability affects the Narou.rb application, which is a tool for managing novel downloads. The issue allows attackers to inject and execute arbitrary Ruby code via the title name or author name of a novel (NVD, RyotaK Advisory).

Technical details

The vulnerability is classified as CWE-94 (Code Injection) and received a CVSS v3.1 Base Score of 9.8 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The issue stems from insufficient validation of novel information, specifically in the handling of title names and author names, which could be crafted to contain malicious Ruby code that would then be executed by the application (NVD).

Impact

The vulnerability allows attackers to execute arbitrary code on the system where Narou.rb runs. Due to the critical CVSS score and the nature of code injection vulnerabilities, this could lead to complete system compromise, allowing attackers to execute commands with the same privileges as the Narou.rb application (NVD).

Exploitability

The vulnerability can be exploited by crafting a malicious novel with specially formatted title or author names containing Ruby code. The attack requires no special privileges or user interaction, making it highly exploitable (RyotaK Advisory).

Mitigation and workarounds

The vulnerability was fixed in Narou.rb version 3.8.0, released on June 27, 2021. Users are strongly recommended to upgrade to version 3.8.0 or later to address this security issue. No workarounds are available for users who cannot upgrade (Narou Changelog).

Community reactions

The vulnerability was discovered and reported by security researcher RyotaK, who was acknowledged in the project's changelog. The Narou.rb maintainers responded promptly by releasing a fix in version 3.8.0 (Narou Changelog).

Additional resources


SourceThis report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71847HIGH8.7
  • Ruby logoRuby
  • ruby3.4-json
NoYesAug 07, 2026
CVE-2026-45414HIGH8.5
  • Ruby logoRuby
  • decidim
NoYesAug 06, 2026
CVE-2026-45573MEDIUM6.4
  • Ruby logoRuby
  • decidim-core
NoYesAug 06, 2026
CVE-2026-45415MEDIUM6
  • Ruby logoRuby
  • decidim-verifications
NoYesAug 06, 2026
CVE-2026-45572MEDIUM4.8
  • Ruby logoRuby
  • decidim-core
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management