{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agist_projectgistruby/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gist_project:gist:*:*:*:*:*:ruby:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-105221"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gist (\u003c 6.1.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","supply-chain","ruby","mitm"],"_cs_type":"advisory","_cs_vendors":["RubyGems"],"content_html":"\u003cp\u003eThe gist RubyGem before version 6.1.0 contains a critical security vulnerability involving improper certificate validation. The underlying issue originates in the 'lib/gist.rb' file, where the 'http_connection' method initializes SSL/TLS connections using 'OpenSSL::SSL::VERIFY_NONE'. This configuration explicitly instructs the library to skip peer certificate verification during the HTTPS handshake.\u003c/p\u003e\n\u003cp\u003eBecause of this, any application or CLI tool utilizing this version of the gist gem is susceptible to man-in-the-middle (MITM) attacks if the traffic is routed through a network segment controlled or accessible by an on-path adversary. Attackers can intercept requests to the GitHub API, present fraudulent certificates, and gain full visibility into or modify the traffic. This exposure allows for the exfiltration of sensitive information, including OAuth tokens, personal access tokens, and other login credentials, which can then be used to gain unauthorized access to and modify a victim's hosted gists.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the interception and manipulation of communications between a user and the GitHub API. An attacker can gain control over sensitive authentication credentials, such as OAuth tokens, leading to full account compromise regarding the management of gists. This threat is particularly relevant to developers and automated CI/CD pipelines that rely on the gist gem for internal or public code sharing.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'gist' RubyGem to version 6.1.0 or later immediately to resolve the hardcoded 'VERIFY_NONE' configuration (CVE-2026-105221).\u003c/li\u003e\n\u003cli\u003eReview environments where the 'gist' gem is deployed, such as CI/CD runners or developer workstations, to identify and update vulnerable instances.\u003c/li\u003e\n\u003cli\u003eAudit logs for unexpected outbound network connections originating from systems where the 'gist' gem is installed, specifically targeting traffic directed toward non-GitHub IP ranges or unauthorized endpoints if possible.\u003c/li\u003e\n\u003cli\u003eConsider implementing man-in-the-middle proxy testing in local development environments to confirm that SSL/TLS certificate validation is strictly enforced across all outbound API integrations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T00:56:25Z","date_published":"2026-10-05T00:56:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-gist-ruby-gem-vulnerability/","summary":"The gist RubyGem versions prior to 6.1.0 contain an improper certificate validation vulnerability that allows on-path attackers to intercept and modify GitHub API traffic by exploiting the hardcoded use of OpenSSL::SSL::VERIFY_NONE.","title":"Improper SSL/TLS Certificate Validation in gist RubyGem","url":"https://feed.craftedsignal.io/briefs/2026-10-gist-ruby-gem-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gist_project:gist:*:*:*:*:*:ruby:*:*","version":"https://jsonfeed.org/version/1.1"}