

Exploit for CVE-2026-66066 against Rails Active Storage/libvips: pre-auth arbitrary file read to recover SECRET_KEY_BASE and achieve RCE, with…

PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Test cases for broken MIME and tools to generate and process these

Ruby on Rails framework for managing and executing phishing campaigns, including email templates, landing pages, and campaign tracking.

Proof-of-concept exploit for CVE-2018-3760, a path traversal vulnerability in Ruby on Rails. Demonstrates the flaw for testing and educational…

Proof-of-concept exploit for CVE-2012-2661, an SQL injection vulnerability in Ruby on Rails ActiveRecord. Includes a write-up in Malay demonstrating…

A vulnerable version of Rails that follows the OWASP Top 10

Rails Asset Pipeline Directory Traversal Vulnerability

Proof-of-concept exploit for CVE-2019-5418, demonstrating file content disclosure on Ruby on Rails via crafted Accept headers, with a demo…

RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

Ruby on Rails test case demonstrating CVE-2019-5418 file content disclosure via path traversal in Accept header, with PoC and reproduction steps.

Step-by-step exploit for Ruby on Rails CVE-2019-5420 RCE via insecure Marshal deserialization, with payload generation and reverse shell capture.

Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit

Proof-of-concept exploit for CVE-2016-2098, demonstrating remote code execution via template injection in Rails 4.2.5.1 view rendering.

Silly Rails App to demonstrate vuln CVE-2013-0156

Pseudo shell for exploiting CVE-2013-0156, providing a command-line interface for automated exploitation of the Ruby on Rails XML/YAML parser…