CVE-2019-5418

HIGH KEV NUCLEI LAB

Ruby On Rails File Content Disclosure (

Title source: metasploit

Description

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

Exploits (12)

exploitdb WORKING POC
by NotoriousRebel · pythonwebappsmultiple
https://www.exploit-db.com/exploits/46585
nomisec WORKING POC 201 stars
by mpgn · infoleak
https://github.com/mpgn/CVE-2019-5418
nomisec WORKING POC 133 stars
by mpgn · infoleak
https://github.com/mpgn/Rails-doubletap-RCE
nomisec SCANNER 35 stars
by brompwnie · poc
https://github.com/brompwnie/CVE-2019-5418-Scanner
nomisec SCANNER 5 stars
by random-robbie · remote
https://github.com/random-robbie/CVE-2019-5418
nomisec WORKING POC 5 stars
by omarkurt · poc
https://github.com/omarkurt/CVE-2019-5418
nomisec WORKING POC 3 stars
by Bad3r · infoleak
https://github.com/Bad3r/RailroadBandit
nomisec WORKING POC 2 stars
by kailing0220 · remote
https://github.com/kailing0220/CVE-2019-5418
nomisec WORKING POC
by daehyeok0618 · infoleak
https://github.com/daehyeok0618/CVE-2019-5418
nomisec WORKING POC
by ztgrace · poc
https://github.com/ztgrace/CVE-2019-5418-Rails3
nomisec WORKING POC
by melardev · poc
https://github.com/melardev/CVE-2019-5418
metasploit WORKING POC
by Carter Brainerd <[email protected]>, John Hawthorn <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/rails_doubletap_file_read.rb

Nuclei Templates (1)

Rails File Content Disclosure
HIGHby omarkurt
Shodan: cpe:"cpe:2.3:a:rubyonrails:rails"

Scores

CVSS v3 7.5
EPSS 0.9432
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull mysql:5.6
docker pull redis:latest
docker pull nginx:1.15
+8 more repos

Details

CISA KEV 2025-07-07
VulnCheck KEV 2025-07-07
ENISA EUVD EUVD-2019-0375
CWE
CWE-22
Status published
Products (8)
debian/debian_linux 8.0
fedoraproject/fedora 30
opensuse/leap 15.0
redhat/cloudforms 4.7
redhat/cloudforms 4.6
redhat/software_collections 1.0
rubygems/actionview 5.2.0 - 5.2.2.1RubyGems
rubyonrails/rails 3.0.0 - 4.2.11.1
Published Mar 27, 2019
KEV Added Jul 07, 2025
Tracked Since Feb 18, 2026