<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Gist (&lt; 6.1.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gist--6.1.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 00:56:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gist--6.1.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper SSL/TLS Certificate Validation in gist RubyGem</title><link>https://feed.craftedsignal.io/briefs/2026-10-gist-ruby-gem-vulnerability/</link><pubDate>Mon, 05 Oct 2026 00:56:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gist-ruby-gem-vulnerability/</guid><description>The gist RubyGem versions prior to 6.1.0 contain an improper certificate validation vulnerability that allows on-path attackers to intercept and modify GitHub API traffic by exploiting the hardcoded use of OpenSSL::SSL::VERIFY_NONE.</description><content:encoded><![CDATA[<p>The gist RubyGem before version 6.1.0 contains a critical security vulnerability involving improper certificate validation. The underlying issue originates in the 'lib/gist.rb' file, where the 'http_connection' method initializes SSL/TLS connections using 'OpenSSL::SSL::VERIFY_NONE'. This configuration explicitly instructs the library to skip peer certificate verification during the HTTPS handshake.</p>
<p>Because of this, any application or CLI tool utilizing this version of the gist gem is susceptible to man-in-the-middle (MITM) attacks if the traffic is routed through a network segment controlled or accessible by an on-path adversary. Attackers can intercept requests to the GitHub API, present fraudulent certificates, and gain full visibility into or modify the traffic. This exposure allows for the exfiltration of sensitive information, including OAuth tokens, personal access tokens, and other login credentials, which can then be used to gain unauthorized access to and modify a victim's hosted gists.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the interception and manipulation of communications between a user and the GitHub API. An attacker can gain control over sensitive authentication credentials, such as OAuth tokens, leading to full account compromise regarding the management of gists. This threat is particularly relevant to developers and automated CI/CD pipelines that rely on the gist gem for internal or public code sharing.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for development and security teams:</p>
<ul>
<li>Upgrade the 'gist' RubyGem to version 6.1.0 or later immediately to resolve the hardcoded 'VERIFY_NONE' configuration (CVE-2026-105221).</li>
<li>Review environments where the 'gist' gem is deployed, such as CI/CD runners or developer workstations, to identify and update vulnerable instances.</li>
<li>Audit logs for unexpected outbound network connections originating from systems where the 'gist' gem is installed, specifically targeting traffic directed toward non-GitHub IP ranges or unauthorized endpoints if possible.</li>
<li>Consider implementing man-in-the-middle proxy testing in local development environments to confirm that SSL/TLS certificate validation is strictly enforced across all outbound API integrations.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>supply-chain</category><category>ruby</category><category>mitm</category></item></channel></rss>