User Impersonation Affecting where_is_waldo package, versions <0.1.6


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUBY-WHEREISWALDO-18309935
  • published26 Jul 2026
  • disclosed25 Jul 2026
  • creditUnknown

Introduced: 25 Jul 2026

New CVE NOT AVAILABLE CWE-290  (opens in a new tab)

How to fix?

Upgrade where_is_waldo to version 0.1.6 or higher.

Overview

Affected versions of this package are vulnerable to User Impersonation via the request.params[:subject_id] parameter when no authenticate_proc is configured. An attacker can gain unauthorized access and impersonate other users by supplying arbitrary subject IDs in the request parameters. This is only exploitable if the built-in ActionCable connection is mounted without configuring authenticate_proc.

CVSS Base Scores

version 4.0
version 3.1