
KindaRails2Shell
Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Proof-of-concept exploit for CVE-2022-32224: Rails ActiveRecord serialized column RCE. Demonstrates YAML deserialization leading to arbitrary class…

Proof-of-concept exploit for CVE-2019-5420 (Rails cookie deserialization) with argparse-based cookie modification, designed for PentesterLab practice.

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Docker-based lab environment for CVE-2019-5418 Ruby on Rails path traversal exploit, with PoC curl commands to read arbitrary server files via…

Python exploit script for CVE-2013-0156, a remote code execution vulnerability in Ruby on Rails via insecure YAML deserialization. Designed for…

Docker-based lab demonstrating CVE-2018-3760 path traversal in Ruby on Rails Sprockets, with POC and environment setup for security testing and…

Proof-of-concept exploit for CVE-2020-8163, a remote code execution vulnerability in Rails < 5.0.1 via user-controlled locals, with a testable…

Reproducible lab for CVE-2026-66066: file-read-to-RCE exploit chain via Ruby on Rails Active Storage and libvips HDF5 matload. Includes Python…

Docker-based lab environment and exploit script for CVE-2020-8163, a blind remote code execution vulnerability in Rails versions before 5.0.1 and…

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

PoC and lab environment for CVE-2023-25950: HTTP request smuggling via malformed header fields in HAProxy's HTTP/3 implementation, enabling DoS and…

A vulnerable version of Rails that follows the OWASP Top 10

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

Reproduction of CVE-2022-36804: pre-authentication remote code execution in Bitbucket Server via null byte injection into git archive arguments.…