depthfirst.com
Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities | depthfirst
We chained two memory-safety flaws in Oj, a native Ruby JSON parser used by GitLab's notebook diff renderer, into remote code execution in a Puma worker. The path begins with an attacker-controlled Jupyter notebook and crosses GitLab, ipynbdiff, CRuby, and jemalloc before reaching function-pointer control.