Savon::Model generated SOAP operation methods by interpolating operation names into Ruby source passed to module_eval. An attacker who can control the operation names of a WSDL, can inject Ruby code that executes in the application process. This affects only the .all_operations class method provided by Savon::Model to automatically register all operations provided by the WSDL. Configuring Savon::Model with trusted operation names via .operations is safe.
Patched in Savon 2.17.2.
Users should upgrade to 2.17.2 or later.
Avoid .all_operations for untrusted WSDL documents. Use .operations with trusted operation names instead.
{
"nvd_published_at": null,
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2026-07-31T19:38:25Z",
"cwe_ids": [
"CWE-94"
]
}