CVE-2019-5420 is a remote code execution vulnerability affecting Ruby on Rails in development mode prior to 5.2.2.1 and 6.0.0.beta3. In affected configurations, Rails may use an automatically generated development-mode secret token that can be guessed by an attacker. If the application is exposed in development mode, an attacker who can derive or guess this secret can combine it with Rails internal mechanisms to escalate the issue into remote code execution. The vulnerability is therefore rooted in predictable or insufficiently protected secret generation in a development-only execution context, with exploitation dependent on the application being deployed or reachable in that insecure mode.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2019-5420, a vulnerability in Ruby on Rails that allows attackers to decrypt, modify, and re-encrypt Rails encrypted cookies. The main file, script.py, is a Python script that takes an application name and an encrypted cookie as input, decrypts the cookie using derived keys (mimicking Rails' encryption logic), allows the user to modify arbitrary key-value pairs in the session data, and then re-encrypts the cookie for use in further attacks. The script uses the cryptography library for AES-GCM decryption/encryption and PBKDF2-HMAC-SHA1 for key derivation. The repository includes a README with usage instructions and an example, a requirements.txt for dependencies, and standard project files (.gitignore, LICENSE). The exploit is operational as a PoC and demonstrates the impact of the vulnerability by enabling session manipulation, which could lead to privilege escalation or user impersonation if the attacker has access to a valid encrypted cookie.
This repository contains a single Metasploit module (modules/exploits/multi/http/rails_double_tap.rb) that exploits CVE-2019-5420, a vulnerability in Ruby on Rails (5.2 and prior) when running in development mode. The exploit leverages the predictable secret_key_base (derived from the application name) to craft a signed, serialized payload that is delivered to the /rails/active_storage/disk/ endpoint. Successful exploitation results in remote code execution on the target server. The module includes logic to extract the application name, generate a malicious payload, and deliver it via HTTP requests. The payload is a stager that writes a base64-encoded executable to /tmp, decodes it, makes it executable, and runs it, allowing for arbitrary code execution. The exploit is operational and customizable within the Metasploit framework.
This repository contains a proof-of-concept (PoC) exploit for CVE-2019-5420, a deserialization vulnerability in Ruby on Rails (ActiveSupport::MessageVerifier). The main exploit script, POC.rb, generates a signed payload that, when deserialized by a vulnerable Rails application, results in remote code execution (RCE). The exploit works by crafting a malicious ERB object containing attacker-controlled code, wrapping it in DeprecatedInstanceVariableProxy, and signing it with a key derived from the application's name. The payload in the PoC executes the command '/usr/local/bin/score Pwned' on the target system, but this can be changed to any arbitrary command. The repository is structured with a single Ruby exploit script (POC.rb), a README.md providing detailed usage and background, and a LICENSE file. The exploit targets Rails applications with weak or guessable secret_key_base values and vulnerable deserialization logic. No network endpoints or hardcoded IPs are present, but the attack vector is network-based, as the payload must be delivered to the vulnerable application.
This repository contains a Ruby proof-of-concept exploit for CVE-2019-5420, a vulnerability in Ruby on Rails (up to 5.2.2.1) related to the handling of encrypted session cookies. The exploit script (CVE-2019-5420.rb) allows an attacker to decrypt a session cookie from a Rails application running in development mode, modify its contents (such as setting the user_id to 1 for admin access), and re-encrypt the cookie for use in the application. The script requires the attacker to supply a valid session cookie and the application name. The exploit leverages Ruby's OpenSSL and JSON libraries to perform cryptographic operations and manipulate the session data. The repository is structured simply, with the main exploit script and a brief README explaining its usage. No network endpoints or hardcoded IPs are present; the attack is performed locally with respect to the session cookie data.
This repository contains a working exploit for two critical vulnerabilities in Ruby on Rails 5.2.1/5.2.2: CVE-2019-5418 (File Content Disclosure) and CVE-2019-5420 (Deserialization RCE). The exploit is implemented in 'exploit.rb', which automates the attack chain: 1. It first checks if the target Rails application is vulnerable to CVE-2019-5418 by attempting to read /etc/passwd via a crafted Accept header. 2. If vulnerable, it retrieves sensitive files ('config/credentials.yml.enc' and 'config/master.key') using the same file disclosure technique. 3. It then decrypts the credentials to obtain the 'secret_key_base'. 4. Using this key, it crafts a malicious Ruby object payload that exploits CVE-2019-5420 by sending it to the '/rails/active_storage/disk/:encoded_key/test' endpoint, resulting in remote code execution. 5. The exploit supports both reflected command execution (output written to /tmp/result.txt and retrievable via file disclosure) and reverse shell payloads. The repository also includes a full Rails 5.2.1 demo application for testing, but the main exploit logic is in 'exploit.rb'. The attack is network-based and targets HTTP endpoints on the vulnerable Rails server. The exploit is operational and provides a reliable method for achieving RCE on unpatched Rails installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.