๐ต๏ธ RESEARCH & DEEP DIVES
- Critical Ruby on Rails Active Storage Flaw Allows Arbitrary File Read and RCE
CVE-2026-66066
A severe vulnerability in Ruby on Rails Active Storage enables arbitrary file read and remote code execution.- Impacts Ruby on Rails Active Storage versions below 7.2.3.2, 8.0.x below 8.0.5.1, and 8.1.x below 8.1.3.1
- Affects applications using libvips for image variant processing with untrusted user uploads
- Attack exploits libvips unfuzzed operations to read sensitive files like secret_key_base and cloud credentials
- Allows unauthenticated attackers to escalate from file disclosure to remote code execution
- Vulnerability arises from unsafe handling of certain image formats via libvips loaders and savers
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ CVEs & KEV
- Other: 20 CVEs (worst 10.0)