Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-8163

82
FAUCET Score

CVE-2020-8163 is a critical code injection vulnerability affecting Ruby on Rails versions prior to 5.0.1, specifically impacting Debian Linux and Rails installations. An authenticated attacker could exploit this flaw by manipulating the 'locals' argument in a 'render' call to achieve Remote Code Execution (RCE). With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and severe potential impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit code is available via ExploitDB and Nuclei templates, though there is minimal community discussion or media coverage surrounding it.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.0.1CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
82.05%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Nuclei: CVE-2020-8163 · Aug 23, 2020
ExploitDB: EDB-48716 · Jul 26, 2020
This CVE's current EPSS score of 0.8205 is in the 100th percentile among its peer group of 17,844 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

arubapatch availablevia llm_extracted
Fixed in: 4.2.11.3
View patch
arubapatch availablevia llm_extracted
Fixed in: 4.2.11.2
View patch
boidcmspatch availablevia llm_extracted
Fixed in: 4.2.11.2
View patch
libvipspatch availablevia llm_extracted
Fixed in: 5.2.4.3, 6.0.3.1
View patch
libvipspatch availablevia llm_extracted
Fixed in: 4.2.11.3
View patch
libvipspatch availablevia llm_extracted
Fixed in: 4.2.11.2
View patch
markusprojectpatch availablevia llm_extracted
Fixed in: 4.2.11.2
View patch
markusprojectpatch availablevia llm_extracted
Fixed in: 4.2.11.3
View patch
prometheuspatch availablevia llm_extracted
Fixed in: 4.2.11.3
View patch
prometheuspatch availablevia llm_extracted
Fixed in: 4.2.11.2
View patch
rubygemspatch availablevia ghsa
Product: actionviewFixed in: 4.2.11.3

Vendor Advisories (12)

rubygemsGHSA-cr3x-7m39-c6jqhigh

Remote code execution via user-provided local names in ActionView

Jul 7, 2020
libvipsllm-libvips-c00e54d5499e9542HIGH

Rails 5.2.4.3 and 6.0.3.1 have been released

May 18, 2020
prometheusllm-prometheus-07a8af23f4b0d5c7

Rails 4.2.11.3 has been released

May 16, 2020
libvipsllm-libvips-a1cf077e230fe2d5

Rails 4.2.11.3 has been released

May 16, 2020
aruballm-aruba-098ca8d7a9bbc5d5

Rails 4.2.11.3 has been released

May 16, 2020
markusprojectllm-markusproject-8db64678ac5f0eb0

Rails 4.2.11.3 has been released

May 16, 2020
markusprojectllm-markusproject-e569dfc10cc3350d

Rails 4.2.11.2 has been released

May 15, 2020
redhatCVE-2020-8163Important

rubygem-rails: potential remote code execution of user-provided local names

May 15, 2020
aruballm-aruba-863a9ace6c821848

Rails 4.2.11.2 has been released

May 15, 2020
prometheusllm-prometheus-cdb7bf53d1f25ea7

Rails 4.2.11.2 has been released

May 15, 2020
boidcmsllm-boidcms-bccef18f1d7d5f19HIGH

Rails 4.2.11.2 has been released

May 15, 2020
libvipsllm-libvips-b6126cb5d60d5beb

Rails 4.2.11.2 has been released

May 15, 2020

References

packetstormsecurity.com / files/158604/Ruby-On-Rails-5.0.1-Remote-Code-Execution.html
ExploitThird Party AdvisoryVDB Entry
groups.google.com / g/rubyonrails-security/c/hWuKcHyoKh0
Mailing ListPatchThird Party Advisory
hackerone.com / reports/304805
Permissions RequiredThird Party Advisory
lists.debian.org / debian-lts-announce/2020/07/msg00013.html
Mailing ListThird Party Advisory