
New Ruby RCE Gadget Chain Turns Unsafe Marshal.load Into Command Execution
A newly disclosed universal deserialization gadget chain demonstrates that a single unsafe Marshal.load operation can lead to remote command execution on Ruby 4.0.6. The chain reportedly also works unchanged on Ruby versions as far back as 3.3, renewing concerns that Ruby’s native serialization mechanism remains a high-risk attack surface when exposed to untrusted data. The […]
The post New Ruby RCE Gadget Chain Turns Unsafe Marshal.load Into Command Execution appeared first on Cyber Security News.