The flash_tool gem up to and including 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.
milboj flash tool