
CVE-2021-22880
Proof-of-concept exploit for CVE-2021-22880 targeting a Rails server vulnerability. Demonstrates exploitation steps and provides a test environment…

Proof-of-concept exploit for CVE-2021-22880 targeting a Rails server vulnerability. Demonstrates exploitation steps and provides a test environment…

Proof-of-concept exploit for CVE-2018-3760, a path traversal vulnerability in Ruby on Rails. Demonstrates the flaw for testing and educational…

Proof-of-concept exploit for CVE-2020-8165 (Ruby on Rails) demonstrating remote code execution via ERB template injection and deserialization. For…

Docker-based lab environment for CVE-2019-5418 Ruby on Rails path traversal exploit, with PoC curl commands to read arbitrary server files via…

Bash-based proof-of-concept exploit for CVE-2016-2098, targeting Ruby on Rails Action Pack remote code execution via unrestricted render method.

Python exploit script for CVE-2019-5420, targeting Ruby on Rails signed-session AES GCM key brute-forcing to achieve remote code execution in…

Proof-of-concept exploit for CVE-2020-8165, a Ruby on Rails remote code execution vulnerability. Demonstrates exploitation of the unsafe…

Proof-of-concept exploit for CVE-2016-2098, demonstrating remote Ruby code execution through Rails render method abuse; intended for security testing…

Node.js exploit for CVE-2015-3224, achieving unauthenticated RCE on Rails web-console by spoofing X-Forwarded-For to bypass IP whitelist and…

Programmable guardrails for LLM chat apps: enforce input/output rails, block jailbreaks and prompt injections, detect hallucination, and mask…

Demonstrates exploitation of Ruby on Rails CVE-2019-5418, a file disclosure vulnerability, for educational purposes.

Python exploit script for CVE-2013-0156, a remote code execution vulnerability in Ruby on Rails via insecure YAML deserialization. Designed for…

Pseudo shell for exploiting CVE-2013-0156, providing a command-line interface for automated exploitation of the Ruby on Rails XML/YAML parser…

Docker-based lab demonstrating CVE-2018-3760 path traversal in Ruby on Rails Sprockets, with POC and environment setup for security testing and…

Executes remote code on vulnerable Rails applications via YAML deserialization (CVE-2013-0156); designed for CTFs and authorized penetration tests.

Proof-of-concept exploit for CVE-2020-8163, a remote code execution vulnerability in Rails < 5.0.1 via user-controlled locals, with a testable…

Reproducible lab for CVE-2026-66066: file-read-to-RCE exploit chain via Ruby on Rails Active Storage and libvips HDF5 matload. Includes Python…

Python exploit for CVE-2015-3224, bypassing IP whitelist in Ruby on Rails web console to achieve remote code execution with interactive reverse shell.