
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A vulnerable version of Rails that follows the OWASP Top 10

A static analysis security vulnerability scanner for Ruby on Rails applications

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Web-based Source Code Vulnerability Scanner

A project security/vulnerability/risk scanning tool

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

A coverage-guided fuzzer for pure Ruby code and Ruby C extensions

Provides a quick workaround for the segfault bug in Ruby (CVE-2009-1904)

Proof-of-concept exploit for CVE-2016-2098, demonstrating remote Ruby code execution through Rails render method abuse; intended for security testing…

Detects known vulnerabilities in Ruby Gemfile dependencies by scanning for specific CVEs, enabling automated security checks in development pipelines.

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Community-maintained database of Ruby gem security advisories with structured CVE data, CVSS scores, and patched version requirements. Integrates…

This is the main repository for metasm, a free assembler / disassembler / compiler written in ruby

Proof-of-concept exploit for CVE-2020-0601 demonstrating spoofed cryptographic key generation and code signing using OpenSSL and Ruby.
