Vulnerability record · CVE-2019-5418 · published 27 March 2019
CVE-2019-5418: Ruby on Rails Action View file content disclosure via crafted Accept headers
Rubyonrails · Rails
Action View in Ruby on Rails fails to properly handle specially crafted Accept headers, allowing arbitrary files on the target filesystem to be read. The flaw affects multiple Rails branches (4.x, 5.0, 5.1, 5.2 and v3) and was added to CISA KEV in July 2025, so it remains actively targeted despite being patched in 2019.
Description
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityCISA KEV listing, near-maximum EPSS score and public exploit code make this a high-likelihood, high-impact unauthenticated file disclosure.
What it is
Action View in Ruby on Rails fails to properly handle specially crafted Accept headers, allowing arbitrary files on the target filesystem to be read. The flaw affects multiple Rails branches (4.x, 5.0, 5.1, 5.2 and v3) and was added to CISA KEV in July 2025, so it remains actively targeted despite being patched in 2019.
Impact
An unauthenticated attacker can read arbitrary files from the server filesystem, exposing credentials, configuration, source code and other sensitive data that can enable further compromise.
Attack surface
Reachable over the network through HTTP requests to a vulnerable Rails application; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Listed in CISA KEV with a 2025-07-28 remediation due date, and public exploit code exists (Exploit-DB 46585, Packet Storm). EPSS is 0.985 (99.9th percentile), indicating very high predicted exploitation activity.
What to do
- Upgrade Action View/Rails to a fixed release: 5.2.2.1, 5.1.6.2, 5.0.7.2 or 4.2.11.1 (or later).
- Apply vendor patches from Red Hat, Debian, Fedora and openSUSE advisories for packaged Rails.
- If immediate upgrade is not possible, apply the workaround published on the oss-security mailing list and follow vendor mitigation guidance.
- Retire or isolate end-of-life Rails 3.x deployments that cannot be patched.
- Verify no vulnerable Rails version remains in container images or bundled software collections.
Detection
- Inspect web/proxy logs for requests with unusual or malformed Accept headers targeting Rails endpoints.
- Monitor for outbound or file-read patterns consistent with reading sensitive paths such as configuration or credential files.
- Alert on exploitation attempts matching public PoCs for CVE-2019-5418 against Rails applications.
- Audit deployed Rails/Action View versions against the fixed release list.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-5418 to the Known Exploited Vulnerabilities catalog on 7 July 2025 as "Rails Ruby on Rails Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 28 July 2025.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-5418 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5418), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.