
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

A static analysis security vulnerability scanner for Ruby on Rails applications

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

A vulnerable version of Rails that follows the OWASP Top 10


A coverage-guided fuzzer for pure Ruby code and Ruby C extensions

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

This is the main repository for metasm, a free assembler / disassembler / compiler written in ruby

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…

Ruby script to fix quote attribution vulnerability (CVE-2023-45806) in Discourse forums by searching and patching malformed quote blocks with…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render…

Remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data.

A project security/vulnerability/risk scanning tool

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

Proof-of-concept exploit for CVE-2020-0601 demonstrating spoofed cryptographic key generation and code signing using OpenSSL and Ruby.

This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data