A vulnerability was found in ruby-oauth oauth up to 1.1.5. It has been declared as problematic. The affected element is the function
OAuth::Consumer#token_request. The manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability was named CVE-2026-54605. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.