View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Critical Ruby on Rails Active Storage Flaw Allows Arbitrary File Read

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Critical Ruby on Rails Active Storage Flaw Allows Arbitrary File Read and RCE CVE-2026-66066
    A severe vulnerability in Ruby on Rails Active Storage enables arbitrary file read and remote code execution.
    • Impacts Ruby on Rails Active Storage versions below 7.2.3.2, 8.0.x below 8.0.5.1, and 8.1.x below 8.1.3.1
    • Affects applications using libvips for image variant processing with untrusted user uploads
    • Attack exploits libvips unfuzzed operations to read sensitive files like secret_key_base and cloud credentials
    • Allows unauthenticated attackers to escalate from file disclosure to remote code execution
    • Vulnerability arises from unsafe handling of certain image formats via libvips loaders and savers
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ”“ CVEs & KEV

  • Other: 20 CVEs (worst 10.0)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check