The critical vulnerability CVE-2026-105221 in RubyGem Gist allows an attacker who interferes with the connection to bypass TLS certificate checking. The flaw could expose OAuth credentials that the tool uses to communicate with GitHub, as described in the NVD entry and technical issue in the Gist repository.

RubyGem Gist is a command-line tool written in Ruby that sends files or code snippets to the GitHub Gist service. The project repository explains that the tool can use an OAuth access token, which is stored locally for subsequent connections.
The CVE concerns RubyGem Gist TLS certificate verification and not a vulnerability in the GitHub platform. According to the information associated with the NVD registration, versions of the package from 4.0.0 to 6.0.x are affected, with 6.1.0 being the first patched version.
How the vulnerability works in RubyGem Gist
The problem lies in the configuration of the HTTPS connection within the library. The relevant line of code defined the VERIFY_NONE, which means it continued the connection without checking whether the remote server's certificate was valid. Thus, encryption alone was not enough to verify who was on the other end.
The certificate check verifies that the encrypted connection ends up with the server the program requested. If omitted, an intermediary can present their own certificate and terminate a separate connection with each side, without RubyGem Gist detecting the interference.
In a man-in-the-middle attack scenario, the attacker must be able to monitor or influence the path of traffic, for example over an unsecured network. If the program accepts a forged certificate, the intermediary node can decrypt or modify requests to GitHub without being detected.
Public issue #373 describes the potential OAuth token exposure and notes that the setting was present in the lib/gist.rb. This is a technical reference to the project repository, not a confirmation that an attacker actually gained access to user accounts.

What can an attacker intercept?
The severity depends on what is being communicated in the connection and the permissions of the exposed token. The repository reports that the tool uses a credential with Gist permissions; therefore, its exposure could allow unauthorized reading or modification of snippets, depending on the permissions granted by the user.
A leak does not automatically mean a full takeover of every GitHub account. The risk is limited by the scope of the token’s permissions, but even access to just Gists can reveal code, notes, or other information that the user considered private. Organizations should consider whether such snippets contain secrets.
The entry CVE-2026-105221 is classified as improper certificate validation. NVD has a CVSS 4.0 critical score of 9.1, with VulnCheck reporting the score. The high score describes the potential impact; it is not evidence that the vulnerability is being exploited in large numbers or that a real-world incident has been recorded. See the detailed VulnCheck entry.
See also: MCP Python SDK: Stealing OAuth credentials from malicious servers

Which versions are affected and how to fix it
NVD lists package versions from 4.0.0 and before 6.1.0 as affected. Administrators should check the version they are using in their Ruby environment, as well as any dependencies that are locked in Gemfile.lock files or installed via package managers.
The fix for RubyGem Gist is available since version 6.1.0. In the fix commit, the VERIFY_NONE option is replaced with VERIFY_PEER so that the server certificate is properly checked before communication continues. This change directly addresses this vulnerability.
After the upgrade, those who used a vulnerable version on an untrusted network should revoke the old token and create a new one with the necessary permissions. They can also review private Gists for unexpected changes and remove any codes or keys that should not be stored in snippets.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: JeetBot: Malicious Twitch extension leaked OAuth tokens of 31,000 users
Development teams can also limit credential exposure by avoiding the use of widely privileged accounts for automated operations. The SecNews technical team recommends verifying the version and renewing tokens as part of the remediation process, but it is not assumed that the upgrade alone will negate a potential prior leak.
See also: ShinyHunters: Salesforce data theft via OAuth
