Skip to content

ERB has an @_init deserialization guard bypass via def_module / def_method / def_class

High severity GitHub Reviewed Published Apr 21, 2026 in ruby/erb • Updated Apr 24, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts