Thoughtbot maintains a focused portfolio of Ruby on Rails libraries and development tools—including administrate, paperclip, clearance, and cocaine—that serve as widely adopted components in web application stacks. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through web-tier input-handling weakness classes including cross-site request forgery, cross-site scripting, SQL injection, and OS command injection, reflecting the injection-surface risks inherent to middleware and ORM components. Defenders should inventory downstream applications that depend on these libraries, as patching decisions often propagate across multiple services; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thoughtbot over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-0889CRITICAL Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access infor | Nov 13, 2017 | 9.8 | 31 | NO | NO |
CVE-2020-5257HIGH In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query. | Mar 13, 2020 | 8.1 | 25 | NO | NO |
CVE-2021-23435MEDIUM This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to cont | Sep 12, 2021 | 6.1 | 21 | NO | NO |
CVE-2016-3098MEDIUM Cross-site request forgery (CSRF) vulnerability in administrate 0.1.4 and earlier allows remote attackers to hijack the user's OAuth autorization code. | Aug 5, 2022 | 5.4 | 20 | NO | NO |
CVE-2013-4457MEDIUM The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation. | Nov 2, 2013 | 6.8 | 18 | NO | NO |
CVE-2015-2963MEDIUM The thoughtbot paperclip gem before 4.2.2 for Ruby does not consider the content-type value during media-type validation, which allows remote attackers to upload HTML documents and | Jul 10, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thoughtbot.
Media articles that mention a CVE ID that affects a product developed by Thoughtbot — matched by CVE ID, not by vendor name.