
KindaRails2Shell
Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

Monkey-patch gem for CVE-2020-5267 that fixes a timing-based vulnerability in ActionDispatch for Rails 4 and 3, providing a tested security backport…

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

Ruby on Rails framework for managing and executing phishing campaigns, including email templates, landing pages, and campaign tracking.

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

A static analysis security vulnerability scanner for Ruby on Rails applications

Exploit for CVE-2026-66066 against Rails Active Storage/libvips: pre-auth arbitrary file read to recover SECRET_KEY_BASE and achieve RCE, with…

Scans Heroku applications for a critical Rails remote code execution vulnerability (CVE-2013-0333) and identifies unpatched instances requiring…

Go-based scanner for CVE-2019-5418 (Ruby on Rails file disclosure) that reads a list of websites and tests for the vulnerability using a burl-derived…

Proof-of-concept exploit for CVE-2021-22880 targeting a Rails server vulnerability. Demonstrates exploitation steps and provides a test environment…

Docker-based lab demonstrating CVE-2018-3760 path traversal in Ruby on Rails Sprockets, with POC and environment setup for security testing and…

Proof-of-concept exploit for CVE-2012-2661, an SQL injection vulnerability in Ruby on Rails ActiveRecord. Includes a write-up in Malay demonstrating…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

Exploit for Apple CoreGraphics heap overflow (CVE-2014-4377) enabling arbitrary code execution on iOS 7.1.x via crafted PDF used as HTML image.

Public disclosure and patch for CVE-2025-63914, a zip bomb vulnerability in Cinnamon/kotaemon, including PoC and mitigation.