← All repos

railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

appsecowasp-toprailsrubyruby-on-railssecurityvulnerabilities
Browse cluster: Claude AI Agent Frameworks & MCP Tools
1,942commits
43contributors
8languages

Tech stack & purpose

RailsGoat is a deliberately vulnerable web application built on Ruby on Rails that demonstrates real-world security vulnerabilities from the OWASP Top 10. Created by OWASP and built with Rails 8.0 and Ruby 3.4.1, it serves as a hands-on training platform for developers and security professionals to learn how common security flaws like SQL injection, cross-site scripting, authentication issues, and insecure direct object references manifest in Rails applications. The project includes a training mode with a test suite that guides learners through vulnerabilities, detailed wiki tutorials on exploitation and remediation, and support for multiple Rails versions spanning from Rails 3.2 through Rails 8, with optional MySQL configuration for certain vulnerability demonstrations.

Community & reference links

Languages

HTML
54.6%
JavaScript
20.3%
Ruby
15.7%
SCSS
6.1%
CSS
3.2%
Dockerfile
0.1%
Shell
0.0%
Procfile
0.0%

Contributors (top 30 of 43)