Active Storage Vulnerability in Rails Affects Image Upload Security
CVE-2026-66066

9.5CRITICAL

Key Information:

Vendor

Rails

Status
Vendor
CVE Published:
30 July 2026

Badges

๐Ÿ“ˆ Trended๐Ÿ“ˆ Score: 6,780๐Ÿ’ฐ Ransomware๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐ŸŸฃ EPSS 18%๐Ÿ“ฐ News Worthy

What is CVE-2026-66066?

CVE-2026-66066 is a significant vulnerability impacting the Active Storage component of the Rails framework, which is widely used for developing web applications. Active Storage simplifies the management of file uploads, particularly images, allowing developers to integrate file handling seamlessly into their applications. In versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1, this vulnerability allows unsafe operations to be performed on image uploads from untrusted sources, as the framework fails to disable certain libvips operations deemed unsafe. If an attacker uploads a maliciously crafted image, they can potentially exploit this vulnerability to read files within the server's context, including sensitive information such as environment variables and application secrets. This could lead to dire consequences for organizations, as exposure of critical credentials may enable unauthorized access to backend systems, data leaks, and even remote code execution.

Potential impact of CVE-2026-66066

  1. Data Exposure: The vulnerability permits attackers to access sensitive files, such as application configuration and environment variables, which may contain crucial credentials and tokens. This can lead to unauthorized data access or exfiltration.

  2. Remote Code Execution: With the potential to acquire sensitive information, attackers could leverage exposed credentials to execute arbitrary code on the server. This escalation of privileges can result in full system compromise and further attacks within the network.

  3. Reputational Damage: Exploitation of this vulnerability can lead to severe reputational harm for affected organizations. Data breaches or service interruptions caused by unauthorized access not only compromise customer trust but may also result in regulatory repercussions and financial losses.

Affected Version(s)

rails < 7.2.3.2 < 7.2.3.2

rails >= 8.0.0.beta1, < 8.0.5.1 < 8.0.0.beta1, 8.0.5.1

rails >= 8.1.0.beta1, < 8.1.3.1 < 8.1.0.beta1, 8.1.3.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026 - Help Net Security

Hereโ€™s an overview of some of last weekโ€™s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert wonโ€™t

2 weeks ago

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) - IT Security News

2026-08-03 14:08 A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow...

3 weeks ago

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) - Help Net Security

A critical security vulnerability (CVE-2026-66066) in Ruby on Rails may allow attackers to read sensitive files off a server.

3 weeks ago

References

EPSS Score

18% chance of being exploited in the next 30 days.

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ’ฐ

    Used in Ransomware

  • ๐Ÿ“ˆ

    Vulnerability started trending

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.