turbo_boost-commands
Commands to help you build robust reactive applications with Rails & Hotwire.
Activity
- Latest release
- 2y ago
- Total releases
- 29
- Cadence
- ~6 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Dec 23, 2022
| Version | Released | |
|---|---|---|
0.3.2
patch
|
0.3.2
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
0.3.1
patch
|
0.3.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
0.3.0
minor
|
0.3.0
minor
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
0.1.3
patch
|
0.1.3
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.2.1.1
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.1.1
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
0.2.2
patch
|
0.2.2
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
0.2.1
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.1
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
0.2.0
minor
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.2.0
minor
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.1.2
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.2
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
0.1.0
minor
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.1.1
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.1.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.18
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.18
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.0.17
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.17
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.0.16
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.16
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.0.15
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.15
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.0.14
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.14
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.0.13
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.13
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.0.12
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.12
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
0.0.11
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.11
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.10
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.10
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.9
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.9
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.8
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.8
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.7
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.7
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.6
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.6
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.5
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.5
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.4
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.4
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.3
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.3
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.2
patch
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.2
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
0.0.1
initial
1 CVE
CVE-2024-28181
GHSA-mp76-7w5v-pr75
Mar 15, 2024
TurboBoost Commands vulnerable to arbitrary method invocation
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
ImpactTurboBoost Commands has existing protections in place to guarantee that only public methods on Command classes can be invoked; however, the existing checks aren't as robust as they should be. It's possible for a sophisticated attacker to invoke more methods than should be permitted depending on the the strictness of authorization checks that individual applications enforce. Being able to call some of these methods can have security implications. DetailsCommands verify that the class must be a PatchesPatched in the following versions.
WorkaroundsYou can add this guard to mitigate the issue if running an unpatched version of the library.
Affected versions
0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.2
0.0.3
+ 12 more Show less
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.1.1
Fixed in
0.1.3
0.2.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.0.1
initial
Dependencies (24)
+ 16 more
Changelog
|