Vulnerability record · CVE-2019-5420 · published 27 March 2019
CVE-2019-5420: Ruby on Rails development mode secret token guess leads to RCE
Rubyonrails · Rails
Rails versions before 5.2.2.1 and before 6.0.0.beta3 generate a predictable development mode secret token. An attacker who guesses this token can combine it with other Rails internals to achieve remote code execution. The flaw is critical because it allows unauthenticated code execution on exposed development instances.
Description
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 and high EPSS with public exploits make this an urgent risk for any exposed development-mode Rails instance.
What it is
Rails versions before 5.2.2.1 and before 6.0.0.beta3 generate a predictable development mode secret token. An attacker who guesses this token can combine it with other Rails internals to achieve remote code execution. The flaw is critical because it allows unauthenticated code execution on exposed development instances.
Impact
An attacker gains remote code execution on the affected Rails application, allowing full compromise of the server and any data it can access.
Attack surface
The vulnerability is reachable over the network without authentication or user interaction, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N. It applies to Rails applications running in development mode.
Exploitation
Public exploit code exists (ExploitDB, PacketStorm) and EPSS is 0.92144 (99.8th percentile), indicating high likelihood of exploitation, though CISA KEV does not list it.
What to do
- Upgrade Rails to 5.2.2.1, 6.0.0.beta3, or later.
- Never expose Rails development mode to untrusted networks; restrict access to localhost or trusted IPs.
- Set a strong, unique secret_key_base in all environments, including development.
- Apply vendor patches for Debian and Fedora packages as available.
- Monitor for unexpected outbound connections or process execution from Rails servers.
Detection
- Look for requests to Rails development endpoints that attempt to exploit known paths or parameters.
- Monitor for unusual child processes spawned by the Rails server (e.g., shell commands).
- Audit Rails configurations to ensure development mode is not enabled on externally accessible interfaces.
- Check logs for repeated failed attempts to guess secret tokens or unusual session manipulation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-5420 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5420), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.