Vulnerability record · CVE-2020-8163 · published 2 July 2020
CVE-2020-8163: Ruby on Rails render locals code injection enables RCE
Rubyonrails · Rails
Rails versions prior to 5.0.1 allow code injection when an attacker controls the `locals` argument passed to a `render` call, leading to remote code execution. The flaw is a CWE-94 code injection issue in a widely used web framework, so any application that passes untrusted input into render locals is exposed.
Description
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and very high EPSS with public exploit references make this a serious RCE risk, though it requires low privileges and a specific vulnerable code pattern.
What it is
Rails versions prior to 5.0.1 allow code injection when an attacker controls the `locals` argument passed to a `render` call, leading to remote code execution. The flaw is a CWE-94 code injection issue in a widely used web framework, so any application that passes untrusted input into render locals is exposed.
Impact
An attacker who can influence the `locals` argument can execute arbitrary code on the server, gaining full control of the Rails application and its host.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), meaning the attacker must already be able to influence the render locals value, typically through an authenticated or otherwise privileged code path.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.82047 (99.6th percentile) and public exploit references exist, indicating significant real-world exploitation likelihood.
What to do
- Upgrade Rails to 5.0.1 or later, or apply the vendor patch referenced in the Rails security mailing list
- Audit application code for render calls that pass user-controlled data into the `locals` argument and sanitize or reject such input
- Apply the Debian LTS update if running the packaged Rails on Debian
- Restrict privileges and access to code paths that can influence render locals
- Monitor for unexpected outbound connections or process execution from Rails application servers
Detection
- Search application logs and code for render calls where locals values originate from request parameters or other untrusted sources
- Monitor Rails application servers for anomalous child processes or shell commands spawned by the web server user
- Use WAF or request inspection rules to flag requests containing Ruby code patterns in parameters that may reach render locals
- Review HackerOne report 304805 and Packet Storm advisory for exploit payload patterns to build detection signatures
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158604/Ruby-On-Rails-5.0.1-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://groups.google.com/g/rubyonrails-security/c/hWuKcHyoKh0 | Mailing ListPatchThird Party Advisory |
| https://hackerone.com/reports/304805 | Permissions RequiredThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2020/07/msg00013.html | Mailing ListThird Party Advisory |
| http://packetstormsecurity.com/files/158604/Ruby-On-Rails-5.0.1-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://groups.google.com/g/rubyonrails-security/c/hWuKcHyoKh0 | Mailing ListPatchThird Party Advisory |
| https://hackerone.com/reports/304805 | Permissions RequiredThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2020/07/msg00013.html | Mailing ListThird Party Advisory |
Track CVE-2020-8163 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8163), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.