Ruby 4.0.3 fixes a serious ERB deserialization issue (CVE-2026-41316).
https://rubystacknews.com/2026/04/21/ruby-4-0-3-released-critical-erb-deserialization-fix/
ERB#def_method, def_module, def_class bypass the @_init guard → RCE via Marshal.load.
Rails apps are especially exposed.
Upgrade now.
Post a comment