CVE-2026-67986
High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.
amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.
Published 2026-08-13. Last modified 2026-09-08.