GHSA-q66h-m87m-j2q6
### Summary: Remote Code Execution Unsafe handling of request parameters in the RPC HTTP server results in command injection ### Details In lib/bitcoin/rpc/http_server.rb line 30-39, the JSON body of a POST request is parsed into `command` and `args` variables. These values are then passed to `send`, which is used to call an arbitrary class method. However, there is no validation that the provided `command` value is one of the expected RPC methods. This means that an attacker could supply a `command` value such as `system`, and then pass arbitrary system commands into the `args` parameter and achieve remote code execution. ### PoC 1. Start the RPC server 2. Send a request to the RPC server as so: ``` curl -X POST http://127.0.0.1:18443 -H 'Content-Type: application/json' \ -d '{"method":"eval","params":["File.write(\"/tmp/pwned\",\"owned\")"]}' ``` 3. Check the /tmp folder on the machine where the RPC server is being run. If a folder /pwned now exists, the vulnerability is confirmed. ### Impact This vulnerability would impact anyone running the RPC server. The impact is higher for those who are running it publicly exposed to the internet. ### Remediation **Mitigating Factors:** - The RPC server is part of the experimental SPV node feature, which is not documented and has very few users. - The SPV-related features may be removed in future releases.
Properties
- ghsa_id
- GHSA-q66h-m87m-j2q6
- severity
- low
- summary
- Bitcoinrb Vulnerable to Command injection via RPC
- cve_id
- GHSA-q66h-m87m-j2q6
- is_ghsa_only
- true
- ghsa_published
- 2026-02-10T00:21:56Z
- source_url
- https://github.com/advisories/GHSA-q66h-m87m-j2q6
- ghsa_updated
- 2026-02-10T00:22:00Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph