Vulnerability record · CVE-2013-0333 · published 30 January 2013
CVE-2013-0333: Ruby on Rails JSON-to-YAML conversion allows remote code execution
Rubyonrails · Rails
Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 mishandles conversion of JSON data to YAML in lib/active_support/json/backends/yaml.rb, feeding crafted data into a YAML parser through unsafe decoding. Because the parser is reached with attacker-controlled input, this enables remote code execution, SQL injection, or authentication bypass. It is a distinct issue from CVE-2013-0156.
Description
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability than CVE-2013-0156.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 mishandles conversion of JSON data to YAML in lib/active_support/json/backends/yaml.rb, feeding crafted data into a YAML parser through unsafe decoding. Because the parser is reached with attacker-controlled input, this enables remote code execution, SQL injection, or authentication bypass. It is a distinct issue from CVE-2013-0156.
Impact
An unauthenticated remote attacker can execute arbitrary code in the Rails application context, inject SQL, or bypass authentication, depending on how the decoded data is used.
Attack surface
Reachable over the network (AV:N) with no authentication (Au:N) and no user interaction, per the CVSS vector; any endpoint that parses attacker-supplied JSON through the affected YAML backend is exposed.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high (0.95327, 99.863rd percentile), indicating strong likelihood of exploitation activity.
What to do
- Upgrade to Rails 2.3.16 or 3.0.20 (or later) as released by the vendor
- Apply the vendor, Red Hat, Debian, or Apple errata for affected packaged deployments
- Avoid passing untrusted input into the JSON-to-YAML parsing path until patched
- Restrict network exposure of Rails endpoints that accept JSON request bodies
Detection
- Monitor application and web logs for JSON request bodies containing YAML-specific tokens or object tags
- Alert on unexpected outbound connections or process spawning from the Rails application process
- Review database logs for anomalous SQL originating from application queries
- Audit authentication events for bypass patterns on JSON-accepting endpoints
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-0333 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0333), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.