{"id":"CVE-2019-5420","aliases":["GHSA-m42h-mh85-4qgc"],"url":"https://o3.security/vulnerability/CVE-2019-5420","summary":"Use of Insufficiently Random Values in Railties Allows Remote Code Execution","details":"A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.","published":"2019-03-27T14:29:01.720Z","modified":"2026-09-09T03:30:21.504171499Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.92144,"percentile":0.99814,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":11,"affectedPackages":[{"ecosystem":"RubyGems","name":"railties","fixedVersion":"5.2.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/rubyonrails-security/IsQKvDqZdKw"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y43636TH4D6T46IC6N2RQVJTRFJAAYGA/"},{"type":"FIX","url":"https://weblog.rubyonrails.org/2019/3/13/Rails-4-2-5-1-5-1-6-2-have-been-released/"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/152704/Ruby-On-Rails-DoubleTap-Development-Mode-secret_key_base-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/46785/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T03:30:21.504171499Z"}}