
brakeman
A static analysis security vulnerability scanner for Ruby on Rails applications

A static analysis security vulnerability scanner for Ruby on Rails applications

红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Vulnerability scanner using Nmap for scanning and correlating found CPEs with CVEs.



CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Inspect all of your heroku apps to see if they are running a vulnerable version of Rails