criticalREV. 01

CVE-2013-0156Ruby on Rails — Type Casting in Request Parsing to Code Execution

Rails converts structured request bodies into objects without restricting the types, so an unauthenticated request builds whatever the attacker names and runs code on the server.

YOUR NEXT MOVE

Upgrade Rails past 2.3.15, 3.0.19, 3.1.10 or 3.2.11, and rebuild applications that were reachable.

Read the risk

THE VITAL STATS
CVSS score
—/ 10
No score recorded
EPSS probability
99%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Not listed
CVE published
2013-01-13
Exploit published
Not recorded
Confidence
high
Kill chain
initial access
MITRE ATT&CK
T1190
Severity
critical

Attacker needsNetwork access to the application

Fixed inRails 2.3.15, Rails 3.0.19, Rails 3.1.10, Rails 3.2.11

Behind the card

5 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-08-07scrty-crds-pipeline/0.1high
epssapi.first.org2026-08-07scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-08-07claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2013-0156 · CRDS 0.1 · Issued 2026-08-07