securityonline.info 7/30/2026, 4:31:15 AM · external

Critical Rails flaw exposes files, risks RCE via CVE-2026-66066

Critical Rails flaw exposes files, risks RCE via CVE-2026-66066
Developing story vulnerability 2 articles tracked
Ruby on Rails Active Storage flaw (CVE-2026-66066) allows file read and RCE
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in Ruby on Rails Active Storage, tracked as CVE-2026-66066, has been identified, allowing unauthenticated attackers to read arbitrary files, potentially leading to remote code execution. Rated 9.5 on the CVSS scale, this flaw arises from improper handling of the libvips image processor. Rails apps using versions below 7.2.3.2, 8.0.5.1, or 8.1.3.1, and accepting untrusted image uploads, are affected. Users are urged to upgrade to secure versions immediately and rotate application secrets. Researchers have not yet reported any exploitation of this vulnerability in the wild.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline