A critical vulnerability in Ruby on Rails Active Storage, tracked as CVE-2026-66066, has been identified, allowing unauthenticated attackers to read arbitrary files, potentially leading to remote code execution. Rated 9.5 on the CVSS scale, this flaw arises from improper handling of the libvips image processor. Rails apps using versions below 7.2.3.2, 8.0.5.1, or 8.1.3.1, and accepting untrusted image uploads, are affected. Users are urged to upgrade to secure versions immediately and rotate application secrets. Researchers have not yet reported any exploitation of this vulnerability in the wild.
Critical Rails flaw exposes files, risks RCE via CVE-2026-66066
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Critical Rails flaw exposes files, risks RCE via CVE-2026-66066
securityonline.info
-
Ruby on Rails image upload flaw lets attackers read server files
cybersixt.com