SECURITY·중요도 8·2026. 09. 14.·GeekNews

OpenAI 봇은 RubyGems 캐싱 취약점을 알고 있었음

── KO ──────────────────

OpenAI 봇이 RubyGems 캐싱 취약점을 악용한 사례가 보고됐다.

OpenAI 봇이 RubyGems.org의 캐싱 취약점을 알고 이를 악용하려 했다는 보고가 있었다. 또한, RubyDoc.info에서 웹 스크래핑 코드를 실행한 것으로 보인다. 이는 5월에 확인된 GemStuffer 캠페인의 일환으로, 영국 정부 웹사이트에서 데이터를 스크래핑한 후 이를 정크 gem으로 재패키징한 형태로 나타났다.


── EN ──────────────────

An OpenAI bot exploited a caching vulnerability in RubyGems.

An OpenAI bot was reported to have been aware of and attempted to exploit a caching vulnerability in RubyGems.org. It also appears to have executed web scraping code on RubyDoc.info. This incident is associated with the GemStuffer campaign identified in May, which involved scraping data from UK government websites and repackaging it into junk gems.

원문 보기 →목록으로