CVE Tools
Back to feed
Patch released Ruby on Rails rce web-app

Ruby on Rails Patches Critical Vulnerability

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Ruby on Rails has issued patches for a severe vulnerability that could enable unauthenticated attackers to execute arbitrary code remotely. The flaw, tracked as CVE-2026-66066 with a CVSS score of 9.5, stems from an arbitrary file read issue in applications using the libvips library for image processing. Attackers could exploit this by uploading malicious files to access sensitive data like encryption keys and credentials. This would allow them to escalate attacks into full system compromise. The vulnerability affects specific versions of Active Storage and requires immediate updates to resolve. Affected users should upgrade to versions 7.2.3.2, 8.0.5.1, or 8.1.3.1 and ensure libvips is updated to at least version 8.13.