CVE-2016-0752: Ruby on Rails Directory Traversal Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 95.5% chance of exploitation in the next 30 days.

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.2 only
  • Red Hat Software Collections: version 1.0 only
  • Rubyonrails Rails: before 3.2.22.1 (fixed in 3.2.22.1); from 4.0.0, before 4.1.14.1 (fixed in 4.1.14.1); from 4.2.0, before 4.2.5.1 (fixed in 4.2.5.1); version 5.0.0 only
  • Suse Linux Enterprise Module For Containers: version 12 only

Published 2016-02-16. Last modified 2026-06-17.