CVE-2016-0752 is a directory traversal vulnerability in Action View in Ruby on Rails. Affected versions include Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1. The flaw occurs when an application uses the render method with insufficient restriction on attacker-controlled pathname input. By supplying path traversal sequences such as '..' in the pathname, a remote attacker can cause Action View to resolve paths outside the intended template directory and read arbitrary files accessible to the application process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module: 'rails_dynamic_render_code_exec.rb', which exploits CVE-2016-0752, a remote code execution vulnerability in Ruby on Rails applications that use dynamic render paths (e.g., 'render params[:id]'). The exploit works by uploading a malicious file (containing code to fetch and execute a payload) to any POST endpoint that accepts file uploads. The attacker then triggers the vulnerable render path to execute the uploaded file, resulting in remote code execution. The module sets up an HTTP server to deliver a Metasploit-generated ELF payload, which is downloaded and executed on the target. The exploit is weaponized, allowing for customizable payloads and is suitable for both Linux and BSD platforms. The code also includes checks for vulnerability and methods to clean up after exploitation. The main endpoints involved are the vulnerable Rails route (configurable, default '/users'), temporary file paths on the target (e.g., '/tmp/<random>'), the attacker's HTTP server, and the '/proc/self/fd/7' file descriptor for log leakage. The repository is structured as a single Ruby file within the Metasploit framework, focusing solely on this exploit.
This repository is a Proof of Concept (PoC) Rails application designed to demonstrate exploitation of CVE-2016-0752, a remote code execution vulnerability in Ruby on Rails (4.0.8). The vulnerability is present in the UserController, where the 'show' action directly passes user-supplied input (params[:id]) to the 'render' method without sanitization. This allows an attacker to supply a crafted template name, leading to arbitrary code execution on the server. The main attack vector is network-based, targeting the HTTP endpoint '/users/:id' (e.g., http://localhost/users/dashboard). The repository includes all standard Rails application files, with the key vulnerability located in 'app/controllers/user_controller.rb'. The README provides exploitation instructions and references a blog post for further details. This PoC does not include a weaponized or automated exploit script, but provides a vulnerable environment for testing and research.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.