


RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python

Exploits Password Reset Vulnerability in OpenCRX, CVE-2020-7378. Also maintains Stealth by deleting all the password reset mails created by the script

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

CVE-2015-3224 Exploit - Rails Web Console RCE

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

Exploit for the Rails CVE-2019-5420

jackson unserialize

This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data

CVE-2019-5420 (Ruby on Rails)

File Content Disclosure on Rails Test Case - CVE-2019-5418

a demo for Ruby on Rails CVE-2019-5418