CVE-2018-3760 is a path-traversal and information-disclosure vulnerability in the Sprockets asset server. Affected releases mishandle file URI processing and repeated URL decoding during asset resolution. A specially crafted, double-encoded traversal request can cause Sprockets to resolve an asset reference outside the application’s configured asset paths and root directory. Affected versions are Sprockets 2.12.4 and earlier, 3.7.1 and earlier, and 4.0.0.beta7 and earlier. The issue is exposed when the Sprockets server is used to serve assets, including Rails development deployments and production deployments configured for runtime asset compilation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (POC) environment for demonstrating the Ruby on Rails Sprockets path traversal vulnerability (CVE-2018-3760). The repository contains Docker and docker-compose files to set up a vulnerable Rails environment, along with a test file ('flagA') placed in /etc/ for exploitation demonstration. The main documentation (README.md) explains the vulnerability, setup instructions, and provides example HTTP requests that exploit the path traversal flaw to read arbitrary files (such as /etc/passwd) from the server. No exploit code is present; exploitation is performed via crafted HTTP requests. The attack vector is network-based, targeting the web server on port 3000. The repository is structured as a POC for educational and testing purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity directory traversal and arbitrary file-read vulnerability in vulnerable Sprockets versions, demonstrated through Rails asset paths. Double-encoded traversal sequences can be used to retrieve files such as /etc/passwd.
A path-traversal vulnerability in the Rails Sprockets asset pipeline. File-URI handling and double URL-decoding permit bypass of path restrictions; rendering an attacker-controlled .erb template can enable remote code execution under the described conditions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.