A critical vulnerability (CVE-2026-66066, CVSS 9.5) in Ruby on Rails Active Storage allows unauthenticated attackers to read arbitrary server files through crafted image uploads. Rails 7.0 and 7.1, which are end-of-life, remain unpatched.
9 reportsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Critical flaw in Ruby on Rails Active Storage allows unauthenticated attackers to read arbitrary server files. Rails 7.0 and 7.1 are end-of-life with no patches https:// deafnews.it/en/article/rails-a ctive-storage-exposes-arbitrary-files-the-eol-window-that-forces-the-issue
Rails Active Storage Exposes Arbitrary Files: The 'EOL Window' That Forces the Issue A critical flaw in Ruby on Rails Active Storage lets unauthenticated attackers read arbitrary server files via crafted image uploads. Rails 7.0 and 7.1 are end-of-life and will not receive patches, forcing urgent major upgrades.
‼️ WARNING -- Critical Rails flaw CVE-2026-66066 could let unauthenticated attackers read server files through crafted image uploads. The bug affects apps using Active Storage with Vips. Stolen Rails keys, database credentials, cloud keys, and API tokens could enable RCE. Patch now. Read the full story - https:// thehackernews.com/2026/07/crit ical-rails-flaw-could-let.html
Critical Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read Ruby on Rails patched a critical vulnerability (CVE-2026-66066) in Active Storage that allows unauthenticated attackers to read arbitrary server files and steal sensitive secrets. **Update Rails immediately to a patched version (7.2.3.2, 8.0.5.1, or 8.1.3.1) and make sure libvips is upgraded to 8.13 or later. A public ex
Critical Rails Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code https:// cybersecuritynews.com/critical -rails-vulnerability/ Ruby on Rails released emergency patches for CVE-2026-66066 (also called KindaRails2Shell), a critical vulnerability in Active Storage’s default libvips image-variant processing. An unauthenticated attacker who can upload images can craft a file that c
Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. https:// thehackernews.com/2026/07/crit ical-rails-flaw-could-let.html?_m=3n%2e009a%2e4043%2ebk0aof3yrl%2e33lb
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https:// ethiack.com/info-hub/research/ kindarails2shell-rails-rce-cve-2026-66066
New. Rapaid7: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails https://www. rapid7.com/blog/post/etr-kinda rails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/ @ Rapid7Official The related Ruby on Rails advisory was published yesterday: Possible arbitrary file read and remote c