What should he have reported to rails security team? Shouldn't he have been contacting GH security team instead?
Edit: Rails guides discusses the root cause and counter measures against these type of vulnerabilities http://guides.rubyonrails.org/security.html#mass-assignment