Rails CVE-2026-66066: Active Storage Flaw Enables Arbitrary File Read and RCE
The Rails project disclosed CVE-2026-66066 this week, a critical vulnerability in Active Storage's variant processing that could allow arbitrary file reads and remote code execution. Apps are at risk if they use libvips as the variant processor and allow untrusted users to upload images that trigger variant generation. Affected versions include Active Storage 8.0, 8.1, and 8.13, and developers are urged to upgrade immediately. Beyond patching, the advisory strongly recommends rotating all application secrets, as credentials may already have been exposed if the app was previously vulnerable. On libvips 8.13 or newer, a workaround exists via the VIPS_BLOCK_UNTRUSTED environment variable or a ruby-vips initializer call, but no workaround is available for older libvips versions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in