Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-14001

33
FAUCET Score

CVE-2020-14001 is a critical vulnerability in the kramdown Ruby gem, affecting products like Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum. It allows unauthenticated attackers to achieve arbitrary file read or embedded Ruby code execution due to improper processing of the 'template' option within Kramdown documents. With a CVSS score of 9.8, this vulnerability poses a severe risk of complete compromise of confidentiality, integrity, and availability. While there are no public exploits or KEV entries, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.0CPE matchmatch criteria
cpe:2.3:a:kramdown_project:kramdown:*:*:*:*:*:ruby:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.56%
Probability of exploitation in next 30 days
EPSS Percentile
90.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0456 is in the 84th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: kramdownFixed in: 2.3.0

Vendor Advisories (2)

rubygemsGHSA-mqm2-cgpr-p4m6critical

Unintended read access in kramdown gem

Aug 7, 2020
redhatCVE-2020-14001Important

rubygem-kramdown: processing template options inside documents allows unintended read access or embedded Ruby code execution

Jun 27, 2020

References

github.com / gettalong/kramdown
Third Party Advisory
github.com / gettalong/kramdown/commit/1b8fd33c3120bfc6e5164b449e2c2fc9c9306fde
PatchThird Party Advisory
github.com / gettalong/kramdown/compare/REL_2_2_1...REL_2_3_0
PatchThird Party Advisory
kramdown.gettalong.org
Vendor Advisory
kramdown.gettalong.org / news.html
Release NotesVendor Advisory
lists.apache.org / thread.html/r96df7899fbb456fe2705882f710a0c8e8614b573fbffd8d12e3f54d2%40%3Cnotifications.fluo.apache.org%3E
lists.debian.org / debian-lts-announce/2020/08/msg00014.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ENMMGKHRQIZ3QKGOMBBBGB6B4LB5I7NQ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/KBLTGBYU7NKOUOHDKVCU4GFZMGA6BP4L
rubygems.org / gems/kramdown
Third Party Advisory
security.netapp.com / advisory/ntap-20200731-0004
Third Party Advisory
usn.ubuntu.com / 4562-1
Third Party Advisory
debian.org / security/2020/dsa-4743
Third Party Advisory