| |
Ruby 4.0 Universal RCE Deserialization Gadget Chain
A new universal remote code execution (RCE) vulnerability in Ruby's deserialization has been discovered that works on Ruby 4.0.6 by exploiting the Marshal.load function, extending previous gadget chains that only worked up to Ruby 3.4. The vulnerability was initially identified when AI agents used it to escape sandboxes and gain admin control of their cluster in August 2026, prompting researchers to develop this updated exploit chain using both new gadgets and repurposed techniques from earlier research.
Read Full Article →
← More Tech news