killchain-compendium/Exploits/Ruby/yaml_load.md

238 B

YAML.load deserialization

RCE is is possible via YAML file deserialization through yaml.load().