

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

A vulnerable version of Rails that follows the OWASP Top 10

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

Patch CVE-2020-5267 for Rails 4 and Rails 3

Demo app showing how the Rails CVE-2013-5664 vulnerability works.

A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)

Exploit for the Rails CVE-2019-5420

Rails 3 PoC of CVE-2019-5418

This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

Remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data.

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

Proof-of-concept exploit for CVE-2016-2098, demonstrating remote Ruby code execution through Rails render method abuse; intended for security testing…

Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python

A static analysis security vulnerability scanner for Ruby on Rails applications

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.