Critical Rails Flaw CVE-2026-66066 Enables File Theft and Remote Code Execution
JPCERT/CC published an advisory on July 30, 2026, warning of a critical vulnerability tracked as CVE-2026-66066 in Ruby on Rails' Active Storage component. The flaw allows unauthenticated attackers to upload a crafted file and trigger malicious variant processing through libvips, potentially reading arbitrary files and stealing sensitive credentials. Under certain conditions, attackers can escalate to full remote code execution running under the Rails process's OS permissions, with no user interaction required. Affected versions include Rails releases earlier than 7.2.3.2, 8.0 to 8.0.5.1, and 8.1 to 8.1.3.1, particularly when the variant processor is set to :vips with a default libvips build. Administrators are advised to upgrade to patched versions immediately and treat all readable credentials as already compromised.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in