Answer in brief
CVE-2024-28181 records a High severity (CVSS 8.1) vulnerability in TurboBoost Commands vulnerable to arbitrary method invocation. The current sources do not mark it as known exploited. The current feed maps @turbo-boost/commands (npm), @turbo-boost/commands (npm), turbo_boost-commands (rubygems), turbo_boost-commands (rubygems). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps @turbo-boost/commands (npm), @turbo-boost/commands (npm), turbo_boost-commands (rubygems), turbo_boost-commands (rubygems). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| @turbo-boost/commandsnpm | >=0 <0.1.3 | 0.1.3 |
| @turbo-boost/commandsnpm | >=0.2.0 <0.2.2 | 0.2.2 |
| turbo_boost-commandsrubygems | >=0 <0.1.3 | 0.1.3 |
| turbo_boost-commandsrubygems | >=0.2.0 <0.2.2 | 0.2.2 |
Published upstream
Mar 15, 2024
Evidence: source:osv:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:osv:source_dates:source-dates:recordFirst seen by HOL
Sep 10, 2026
### Impact TurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. #### Details Commands verify that the class must be a `Command` and that the method requested is defined as a public method; however, this isn't robust enough to guard against all unwanted code execution. The library should more strictly enforce which methods are considered safe before allowing them to be executed. ### Patches Patched in the following versions. - 0.1.3 - [NPM Package](https://www.npmjs.com/package/@turbo-boost/commands/v/0.1.3) - [Ruby GEM](https://rubygems.org/gems/turbo_boost-commands/versions/0.1.3) - 0.2.2 - [NPM Package](https://www.npmjs.com/package/@turbo-boost/commands/v/0.2.2) - [Ruby GEM](https://rubygems.org/gems/turbo_boost-commands/versions/0.2.2) ### Workarounds You can add this guard to mitigate the issue if running an unpatched version of the library. ```ruby class ApplicationCommand < TurboBoost::Commands::Command before_command do method_name = params[:name].include?("#") ? params[:name].split("#").last : :perform ancestors = self.class.ancestors[0..self.class.ancestors.index(TurboBoost::Commands::Command) - 1] allowed = ancestors.any? { |a| a.public_instance_methods(false).any? method_name.to_sym } throw :abort unless allowed # ← blocks invocation # raise "Invalid Command" unless allowed # ← blocks invocation end end ```
Quoted source text, attributed separately from HOL analysis.