Ruby: Remote code execution (GLSA 202609-03)
A vulnerability has been discovered in Ruby, possibly allowing remote code execution.
Ruby is an interpreted scripting language for quick and easy object-oriented programming.
A vulnerability has been discovered in Ruby. Please review the CVE identifier referenced below for details.
Remote code execution is possible.
There is no known workaround at this time.
All Ruby 3.3 users should upgrade to the latest version:
All Ruby 3.4 users should upgrade to the latest version:
All Ruby 4.0 users should upgrade to the latest version:
All ERB users should upgrade to the latest version:
Release date September 12, 2026
Latest revision September 12, 2026: 1
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
