Most CVEs that come to mind assume a somewhat determined attacker.
It takes a reasonably determined attacker to commit to rails without permission [1] or run a ten-line perl script to crash a server [2] too.
Waving away a problem via "the bad guys would need to think for more than one second" is not exactly reassuring.
[1]: https://github.com/rails/rails/commit/b83965785db1eec019edf1...