
brakeman
A static analysis security vulnerability scanner for Ruby on Rails applications

A static analysis security vulnerability scanner for Ruby on Rails applications

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

A vulnerable version of Rails that follows the OWASP Top 10


Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.


Rails 3 PoC of CVE-2019-5418

Patch CVE-2020-5267 for Rails 4 and Rails 3

Exploit for the Rails CVE-2019-5420

Remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data.

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data

Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python

A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)

Demo app showing how the Rails CVE-2013-5664 vulnerability works.