
KindaRails2Shell
Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

Exploit for Rails CVE-2019-5420 targeting insecure session key derivation in development mode, enabling remote code execution via crafted requests.

Dockerized exploit environment for CVE-2019-5420 (Ruby on Rails Active Storage) enabling remote code execution. Designed for educational testing and…

Proof-of-concept exploit for CVE-2022-32224: Rails ActiveRecord serialized column RCE. Demonstrates YAML deserialization leading to arbitrary class…

Proof-of-concept exploit for CVE-2019-5420 (Rails cookie deserialization) with argparse-based cookie modification, designed for PentesterLab practice.

Proof-of-concept exploit for CVE-2019-5420, a remote code execution vulnerability in Ruby on Rails, designed for educational purposes.

Exploit for CVE-2026-66066 against Rails Active Storage/libvips: pre-auth arbitrary file read to recover SECRET_KEY_BASE and achieve RCE, with…

Python exploit for CVE-2020-8165 targeting Rails MemCacheStore and RedisCacheStore. Enables remote command execution via user-provided object…

Automated exploit script for CVE-2020-8165 targeting Rails applications, enabling remote code execution via crafted payloads.

Proof-of-concept exploit for CVE-2019-5420 targeting Rails development mode secret token disclosure to escalate privileges via cookie manipulation.

Step-by-step exploit for Ruby on Rails CVE-2019-5420 RCE via insecure Marshal deserialization, with payload generation and reverse shell capture.

Proof-of-concept exploit for CVE-2016-0752, a Rails dynamic render remote code execution vulnerability, with setup instructions and reference to a…

Bootstrapped Rails 3.2.10 to test the remote code exploit CVE-2013-0156

Go-based scanner for CVE-2019-5418 (Ruby on Rails file disclosure) that reads a list of websites and tests for the vulnerability using a burl-derived…

Proof-of-concept exploit for CVE-2021-22880 targeting a Rails server vulnerability. Demonstrates exploitation steps and provides a test environment…

Proof-of-concept exploit for CVE-2018-3760, a path traversal vulnerability in Ruby on Rails. Demonstrates the flaw for testing and educational…

Proof-of-concept exploit for CVE-2020-8165 (Ruby on Rails) demonstrating remote code execution via ERB template injection and deserialization. For…