
brakeman
A static analysis security vulnerability scanner for Ruby on Rails applications
code-analysisdevsecopsstatic-analysis+2
7.3k8 days ago

A static analysis security vulnerability scanner for Ruby on Rails applications

A vulnerable version of Rails that follows the OWASP Top 10

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…