
brakeman
A static analysis security vulnerability scanner for Ruby on Rails applications

A static analysis security vulnerability scanner for Ruby on Rails applications

A vulnerable version of Rails that follows the OWASP Top 10

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python

Remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data.

This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data

Demo app showing how the Rails CVE-2013-5664 vulnerability works.

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

Patch CVE-2020-5267 for Rails 4 and Rails 3

A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)


CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

Rails 3 PoC of CVE-2019-5418

Exploit for the Rails CVE-2019-5420
