CVE-2019-5418

HIGH KEV NUCLEI

Ruby On Rails File Content Disclosure (

Title source: metasploit

Description

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

Exploits (12)

nomisec WORKING POC 201 stars
by mpgn · infoleak
https://github.com/mpgn/CVE-2019-5418
nomisec WORKING POC 133 stars
by mpgn · infoleak
https://github.com/mpgn/Rails-doubletap-RCE
nomisec SCANNER 35 stars
by brompwnie · poc
https://github.com/brompwnie/CVE-2019-5418-Scanner
nomisec SCANNER 5 stars
by random-robbie · remote
https://github.com/random-robbie/CVE-2019-5418
nomisec WORKING POC 5 stars
by omarkurt · poc
https://github.com/omarkurt/CVE-2019-5418
nomisec WORKING POC 3 stars
by Bad3r · infoleak
https://github.com/Bad3r/RailroadBandit
nomisec WORKING POC 2 stars
by kailing0220 · remote
https://github.com/kailing0220/CVE-2019-5418
nomisec WORKING POC
by ztgrace · poc
https://github.com/ztgrace/CVE-2019-5418-Rails3
nomisec WORKING POC
by melardev · poc
https://github.com/melardev/CVE-2019-5418
nomisec WORKING POC
by daehyeok0618 · infoleak
https://github.com/daehyeok0618/CVE-2019-5418
exploitdb WORKING POC
by NotoriousRebel · pythonwebappsmultiple
https://www.exploit-db.com/exploits/46585
metasploit WORKING POC
by Carter Brainerd <[email protected]>, John Hawthorn <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/rails_doubletap_file_read.rb

Nuclei Templates (1)

Rails File Content Disclosure
HIGHby omarkurt
Shodan: cpe:"cpe:2.3:a:rubyonrails:rails"

Scores

CVSS v3 7.5
EPSS 0.9434
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation Intel

CISA KEV 2025-07-07
VulnCheck KEV 2025-07-07
ENISA EUVD EUVD-2019-0375

Classification

CWE
CWE-22
Status published

Affected Products (8)

rubyonrails/rails < 4.2.11.1
debian/debian_linux
redhat/cloudforms
opensuse/leap
fedoraproject/fedora
redhat/cloudforms
redhat/software_collections
rubygems/actionview < 5.2.2.1RubyGems

Timeline

Published Mar 27, 2019
KEV Added Jul 07, 2025
Tracked Since Feb 18, 2026