A critical vulnerability in Ruby on Rails Active Storage, tracked as CVE-2026-66066, has been identified, allowing unauthenticated attackers to read arbitrary files, potentially leading to remote code execution. Rated 9.5 on the CVSS scale, this flaw arises from improper handling of the libvips image processor. Rails apps using versions below 7.2.3.2, 8.0.5.1, or 8.1.3.1, and accepting untrusted image uploads, are affected. Users are urged to upgrade to secure versions immediately and rotate application secrets. Researchers have not yet reported any exploitation of this vulnerability in the wild.
Critical Rails flaw exposes files, risks RCE via CVE-2026-66066
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CVE-2026-66066 Ruby on Rails Flaw Triggers Remote Code Execution
securityweek.com
-
CVE-2026-66066 flaw lets attackers read files in Ruby on Rails
rapid7.com
-
Ruby on Rails fixes critical Active Storage bug CVE-2026-66066
securityaffairs.com
-
Ruby on Rails Patches Critical Vulnerability
securityweek.com
-
CVE-2026-66066: Rails Active Storage RCE Exploit Code Now Public
securityonline.info
-
Critical Ruby on Rails Bug Exposes Files via Image Upload
rapid7.com
-
Critical Rails flaw exposes files, risks RCE via CVE-2026-66066
securityonline.info