logo

Ruby ERB Template Injection

ID: 6d318f95-7e39-5fc2-98ea-4c78482864e4

STIX ID: report--6d318f95-7e39-5fc2-98ea-4c78482864e4

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog-style walkthrough demonstrates a server-side template injection vulnerability in Ruby/ERB. The authors show how to confirm injection, enumerate objects and methods via introspection, and craft payloads that access the server's SSL context to recover the private key—highlighting how unsafe server-side template processing can lead to severe data exposure and potential remote code execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.