RubyGems disclosed on HackerOne: Remote code execution on rubygems.org

An unsafe object deserialization vulnerability was found in RubyGems. Unfortunately this vulnerability can be used as a way to escalate to a remote code execution exploit.