How “../sms” could bypass Authy everywhere
sakurity.com
sakurity.com
Seriously though, it's very worrying to me that so many low-level ruby libraries have so many issues. I realise bugs happen, but at least in the python world there seems to be less "oh whoops the most popular OAuth provider lib is susceptible to CSRF"-type bugs.