Ruby Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2019-16255
Ruby through 2.4.7 2.5.x through 2.5.6 and 2.6.x through 2.6.4 allows code injection if the first argument (aka the quotcommandquot argument) to Shell or Shelltest in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.