Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jul 28, 2025

CVE-2019-5418

High
EPSS 94.3%CISA KEV
Rails/Ruby on Rails

Description

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

EPSS — Exploit Probability

94.3%

Higher than 100.0% of all CVEs

Required Action

https://web.archive.org/web/20190313201629/https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/ ; https://nvd.nist.gov/vuln/detail/CVE-2019-5418

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
94.3%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Jul 7, 2025

Added to KEV

Jul 7, 2025

Remediation Due

Jul 28, 2025

Affected Product

Rails

Ruby on Rails

View all Rails CVEs