Exploited Vulnerabilities Daily
🌐 English

Home › Rails

CVE-2019-5418: Rails Ruby on Rails

EPSS98.5%No. 251 of 1739 in KEV
CVE year2019~6 yrs before listing
Same vendor in KEV3
Same product3
FieldValue
VendorRails
ProductRuby on Rails
NameRails Ruby on Rails Path Traversal Vulnerability
Added to KEV2025-07-07
US federal due date2025-07-28
Ransomware useUnknown
CWECWE-22

CISA description

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2016-0752Rails Ruby on Rails2022-03-2595.5%Unknown
CVE-2014-0130Rails Ruby on Rails2022-03-2553.7%Unknown

NVD — CVE-2019-5418

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Rails Ruby on Rails vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-07.