Earlier quoted context omitted.
So you don't have a curl command that exploits it, but you don't believe the authors. That leaves us with what?
Apparently, it leaves you waiting for an upcoming Rails advisory.
Edit: I shouldn't have been so harsh since the author is a security researcher and is probably not doing it out of some grudge. But even from a security researcher, saying he has doubts about a software doesn't make something insecure.
If he can prove his statement that he thinks regular user input is insecure (without requiring the secret session key), then I will happily be convinced of his prowess in finding exploits.