CVE-2019-5418: Rails Ruby on Rails Path Traversal Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2025-07-07. EPSS: 98.5% chance of exploitation in the next 30 days.

There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 30 only
  • Opensuse Leap: version 15.0 only
  • Red Hat Cloudforms: version 4.7 only; version 4.6 only
  • Red Hat Software Collections: version 1.0 only
  • Rubyonrails Rails: from 3.0.0, before 4.2.11.1 (fixed in 4.2.11.1); from 5.0.0, before 5.0.7.2 (fixed in 5.0.7.2); from 5.1.0, before 5.1.6.2 (fixed in 5.1.6.2); from 5.2.0, before 5.2.2.1 (fixed in 5.2.2.1)

Published 2019-03-27. Last modified 2026-06-17.