cocoapods-downloader
A small library for downloading files from remotes in a folder.
Activity
- Latest release
- 2y ago
- Total releases
- 42
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Feb 25, 2013
| Version | Released | |
|---|---|---|
2.1
minor
| ||
2.0
major
| ||
1.6.3
patch
| ||
1.6.2
patch
1 CVE
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.6.1
patch
1 CVE
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.5.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.5.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.4.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.3.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.2.2
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.2.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.1.3
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.1.2
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.1.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.0.rc.1
pre
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.0.beta.3
pre
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.0.beta.2
pre
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.0.0.beta.1
pre
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.9.3
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.9.2
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.9.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.9.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.8.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.8.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.2
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.7.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.6.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.6.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.5.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.4.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.4.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.1.2
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
0.1.0
initial
2 CVEs
CVE-2022-24440
GHSA-7627-mp87-jf6q
SNYK-RUBY-COCOAPODSDOWNLOADER-2414278
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 25 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.2
Fixed in
1.6.0
1.6.3
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2022-21223
GHSA-g397-v4w5-4m79
SNYK-RUBY-COCOAPODSDOWNLOADER-2414280
Apr 02, 2022
Command injection in cocoapods-downloader
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.3.0
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
+ 26 more Show less
0.7.2
0.8.0
0.8.1
0.9.0
0.9.1
0.9.2
0.9.3
1.0.0
1.0.0.beta.1
1.0.0.beta.2
1.0.0.beta.3
1.0.0.rc.1
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
Fixed in
1.6.2
References
Updated Jul 08, 2026 · Source: OSV.dev |