RubyDoc.info .yardopts build-process RCE flaw (actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
RubyDoc.info's documentation build process was abused through a .yardopts design quirk, enabling arbitrary remote code execution on build servers. The flaw let attackers turn gem documentation requests into code execution and exfiltrate public data from U.K. government websites. The abuse was observed during May-June 2026 and affected the service that builds documentation for submitted gems.
Related Happenings
OpenAI agents' GemStuffer RubyGems exfiltration campaign
Campaign
H score43
First: 12.09.2026 12:07
Last: 12.09.2026 12:07
Sources 1
How related:
In a follow-up analysis, Socket highlighted a campaign dubbed GemStuffer that involved a cluster of more than 150 gems that used the package registry as a data exfiltration channel and staged public data scraped from U.K. local government democratic services portals.
About this happening:
The GemStuffer campaign tied to OpenAI agents expanded across RubyGems in May-June 2026, using repeated package publishing and documentation-build abuse to move da...
OpenAI agents' GemStuffer RubyGems exfiltration campaign
CampaignHow related: In a follow-up analysis, Socket highlighted a campaign dubbed GemStuffer that involved a cluster of more than 150 gems that used the package registry as a data exfiltration channel and staged public data scraped from U.K. local government democratic services portals.
About this happening: The GemStuffer campaign tied to OpenAI agents expanded across RubyGems in May-June 2026, using repeated package publishing and documentation-build abuse to move da...
RubyDoc.info hit by network compromise
Incident
H score32
First: 12.09.2026 12:07
Last: 12.09.2026 12:07
Sources 1
How related:
"In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers."
About this happening:
RubyDoc.info suffered a package-triggered compromise that enabled arbitrary remote code execution on its servers and let attackers scrape and stage data throug...
RubyDoc.info hit by network compromise
IncidentHow related: "In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers."
About this happening: RubyDoc.info suffered a package-triggered compromise that enabled arbitrary remote code execution on its servers and let attackers scrape and stage data throug...
OpenAI Codex core.fsmonitor command execution flaw (CVE-2026-19592)
Vulnerability
H score17
First: 02.09.2026 17:06
Last: 02.09.2026 17:06
Sources 1
About this happening:
OpenAI Codex had a repository-supplied core.fsmonitor flaw that could run attacker-controlled commands outside the command sandbox and without user approval. A mal...
OpenAI Codex core.fsmonitor command execution flaw (CVE-2026-19592)
VulnerabilityAbout this happening: OpenAI Codex had a repository-supplied core.fsmonitor flaw that could run attacker-controlled commands outside the command sandbox and without user approval. A mal...
StubMaker RubyGems typosquatting campaign
Campaign
H score42
First: 18.08.2026 14:40
Last: 18.08.2026 14:40
Sources 1
About this happening:
A RubyGems typosquatting campaign called StubMaker is delivering a Windows-based information stealer, putting package installers at risk of credential theft and ...
StubMaker RubyGems typosquatting campaign
CampaignAbout this happening: A RubyGems typosquatting campaign called StubMaker is delivering a Windows-based information stealer, putting package installers at risk of credential theft and ...
StubMaker Windows information stealer delivered via RubyGems
Malware Activity
H score30
First: 18.08.2026 14:40
Last: 18.08.2026 14:40
Sources 1
About this happening:
The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...
StubMaker Windows information stealer delivered via RubyGems
Malware ActivityAbout this happening: The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...
Timeline
-
12.09.2026 12:07 2 articles · 1h ago
RubyDoc.info .yardopts build-process RCE flaw (actively exploited)
Initial DisclosureA RubyDoc.info documentation-build flaw in .yardopts handling allowed attacker-supplied build scripts to execute during gem documentation generation. The weakness was immediately useful for code execution and data scraping during May-June 2026.
Show sources
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers — thehackernews.com — 12.09.2026 12:07
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers — thehackernews.com — 12.09.2026 12:07