
railsgoat
A vulnerable version of Rails that follows the OWASP Top 10
code-analysisctfeducation+5

A vulnerable version of Rails that follows the OWASP Top 10

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

A static analysis security vulnerability scanner for Ruby on Rails applications

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.