file_path

ssrf.rb

discovered 2026-09-18

Attacker payload script filename observed across the GemStuffer / 'OpenAI Swarm' campaign, loaded via a gem's .yardopts '--load' directive to achieve RCE during a RubyDoc.info documentation build.

Campaigns