Security researcher NullSecurityX reported a critical remote code execution (RCE) issue in RubitMQ Ruby job workers caused by unsafe JSON deserialization using the Oj gem. The worker pattern stores user-influenced job payloads as JSON and later processes them with Oj.load, which can reconstruct full Ruby objects (not just primitive JSON types). By abusing Oj’s object directives (e.g., {"^o":"ClassName"}), an attacker can trigger object instantiation and inject state, turning a background-job data channel into code execution and potentially enabling full system/infrastructure compromise.
The exploitation path described relies on design-level trust assumptions and a capability-based dynamic dispatch pattern: the worker checks whether a deserialized object responds to a method (notably run_find) and then executes it, treating method presence as authorization. In the demonstrated RubitMQ scenario, attackers craft a payload that instantiates an application class (e.g., a Node utility class) exposing run_find, which executes shell commands via Open3.capture3, making command execution deterministic. The issue is described as CVE-2024-XXXX with a CVSS 9.8 rating, and mitigations center on eliminating object deserialization of untrusted data (avoid Oj.load on attacker-controlled payloads) and applying required updates/configuration changes in affected RubitMQ/Oj deployments.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Several security news outlets reported a critical deserialization vulnerability affecting Ruby background job workers using Oj.load, including RubitMQ-based patterns. Coverage highlighted that crafted JSON payloads could trigger object injection, invoke dangerous methods such as those using Open3.capture3, and lead to arbitrary command execution and broader infrastructure compromise.
On Medium, researcher NullSecurityX published technical details of a deterministic remote code execution issue in Ruby background workers caused by unsafe JSON deserialization with the Oj gem. The write-up described how attacker-controlled JSON could instantiate application objects and abuse dynamic method dispatch to achieve worker takeover and potential full system compromise.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecyberpress.org
Open sourcegbhackers.com
Open sourcenullsecurityx.medium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.