


Rails Asset Pipeline Directory Traversal Vulnerability

Ruby On Rails unrestricted render() exploit



Enviroment and exploit to rce test

CVE-2016-2098 simple POC written in bash

Ruby on Rails Web Console Exploit (CVE-2015-3224)


RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python

Exploits Password Reset Vulnerability in OpenCRX, CVE-2020-7378. Also maintains Stealth by deleting all the password reset mails created by the script

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

CVE-2015-3224 Exploit - Rails Web Console RCE