E-Ink News Daily

Back to list

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)

A critical remote code execution (RCE) vulnerability, CVE-2026-66066, has been discovered in Ruby on Rails' Active Storage component when using the default vips image processor. The flaw allows attackers to execute arbitrary code if an application accepts untrusted image uploads, affecting most default Rails 7.x/8.x installations and some customized Rails 6.x setups.

Background

This vulnerability affects widely used web frameworks and could lead to severe security breaches if not patched promptly. The discovery highlights the importance of keeping both the framework and its dependencies like libvips up to date.

Source
Lobsters
Published
Jul 30, 2026 at 10:36 PM
Score
9.0 / 10