← Vulnerability feed

Vulnerability record · CVE-2013-0333 · published 30 January 2013

CVE-2013-0333: Ruby on Rails JSON-to-YAML conversion allows remote code execution

Rubyonrails · Rails

Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 mishandles conversion of JSON data to YAML in lib/active_support/json/backends/yaml.rb, feeding crafted data into a YAML parser through unsafe decoding. Because the parser is reached with attacker-controlled input, this enables remote code execution, SQL injection, or authentication bypass. It is a distinct issue from CVE-2013-0156.

7.5 CVSS 2.0 High EPSS 95% · top 0.1%
7.5CVSS 2.0 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability than CVE-2013-0156.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 mishandles conversion of JSON data to YAML in lib/active_support/json/backends/yaml.rb, feeding crafted data into a YAML parser through unsafe decoding. Because the parser is reached with attacker-controlled input, this enables remote code execution, SQL injection, or authentication bypass. It is a distinct issue from CVE-2013-0156.

Impact

An unauthenticated remote attacker can execute arbitrary code in the Rails application context, inject SQL, or bypass authentication, depending on how the decoded data is used.

Attack surface

Reachable over the network (AV:N) with no authentication (Au:N) and no user interaction, per the CVSS vector; any endpoint that parses attacker-supplied JSON through the affected YAML backend is exposed.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is very high (0.95327, 99.863rd percentile), indicating strong likelihood of exploitation activity.

What to do

  • Upgrade to Rails 2.3.16 or 3.0.20 (or later) as released by the vendor
  • Apply the vendor, Red Hat, Debian, or Apple errata for affected packaged deployments
  • Avoid passing untrusted input into the JSON-to-YAML parsing path until patched
  • Restrict network exposure of Rails endpoints that accept JSON request bodies

Detection

  • Monitor application and web logs for JSON request bodies containing YAML-specific tokens or object tags
  • Alert on unexpected outbound connections or process spawning from the Rails application process
  • Review database logs for anomalous SQL originating from application queries
  • Audit authentication events for bypass patterns on JSON-accepting endpoints

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-0333 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2019-5418Ruby on Rails Action View file content disclosure via crafted Accept headersAction View in Ruby on Rails fails to properly handle specially crafted Accept headers, allowing arbitrary files on the target filesystem to be read.…KEVEPSS 99%analysed7.5CVE-2016-0752Ruby on Rails Action View render method directory traversalAction View in Ruby on Rails fails to properly sanitize pathnames passed to the render method, allowing directory traversal via '..' sequences. An ap…KEVEPSS 96%analysed7.5CVE-2014-0130Ruby on Rails implicit-render directory traversal allows arbitrary file readRuby on Rails versions before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1 contain a directory traversal flaw in the implicit-render implementa…KEVEPSS 54%analysed10.0CVE-2013-0277Rubyonrails rails vulnerabilityActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via c…EPSS 7.5%9.8CVE-2024-28103Rubyonrails rails improper input validation vulnerabilityAction Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served o…EPSS 0.66%9.8CVE-2020-8165Ruby on Rails cache store deserialization leads to RCERuby on Rails before 5.2.4.3 and before 6.0.3.1 deserializes untrusted data in MemCacheStore and RedisCacheStore, allowing attacker-supplied objects …EPSS 46%analysed9.8CVE-2019-5420Ruby on Rails development mode secret token guess leads to RCERails versions before 5.2.2.1 and before 6.0.0.beta3 generate a predictable development mode secret token. An attacker who guesses this token can com…EPSS 90%analysed9.8CVE-2009-2422Rubyonrails ruby on rails improper authentication vulnerabilityThe example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_reques…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2013-0333), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.