PkgRadar

RubyGems · rubygems.org

sqlite3

Rb Install Time Backticks: Backtick / %x() shell-out paired with eval/dynamic-require/network/deserialize.

Why PkgRadar flagged 2.9.5

SeveritySignalEvidence
highRb Install Time BackticksBacktick / %x() shell-out paired with eval/dynamic-require/network/deserialize. · ext/sqlite3/extconf.rb
highRb Install Time Unsafe DeserializeMarshal.load / YAML.unsafe_load — RCE if attacker-controlled. · ext/sqlite3/extconf.rb

Scanned versions

VersionVerdictScoreScanned (UTC)
2.9.5Review302026-06-07

Block this in CI

PkgRadar gates sqlite3 (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem rubygems [email protected]