A critical remote code execution (RCE) vulnerability, CVE-2026-66066, has been discovered in Ruby on Rails' Active Storage component when using the default vips image processor. The flaw allows attackers to execute arbitrary code if an application accepts untrusted image uploads, affecting most default Rails 7.x/8.x installations and some customized Rails 6.x setups.
Background
This vulnerability affects widely used web frameworks and could lead to severe security breaches if not patched promptly. The discovery highlights the importance of keeping both the framework and its dependencies like libvips up to date.
- Source
- Lobsters
- Published
- Jul 30, 2026 at 10:36 PM
- Score
- 9.0 / 10