RubyGems · rubygems.org
workos
Rb Install Time Backticks: Backtick subshell or %x() shell-out — runs shell with interpolated input.
Why PkgRadar flagged 9.0.0
| Severity | Signal | Evidence |
|---|---|---|
| high | Rb Install Time Backticks | Backtick subshell or %x() shell-out — runs shell with interpolated input. · workos.gemspec |
| high | Rb Runtime Base64 Decode | Base64.decode64 combined with eval/system — classic obfuscated payload. · lib/workos/encryptors/aes_gcm.rb |
| high | Rb Runtime Base64 Decode | Base64.decode64 combined with eval/system — classic obfuscated payload. · lib/workos/vault.rb |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
9.0.0 | Review | 30 | 2026-05-26 |
Block this in CI
pkgradar gate --ecosystem rubygems [email protected]