converter.rb in the md2pdf gem 0.0.1 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.
converter.rb
md2pdf
{ "last_known_affected_version_range": "<= 0.0.1" }