Patch released Ruby on Rails rce web-app
Ruby on Rails Patches Critical Vulnerability
CVE Tools coverage
Ruby on Rails has issued patches for a severe vulnerability that could enable unauthenticated attackers to execute arbitrary code remotely. The flaw, tracked as CVE-2026-66066 with a CVSS score of 9.5, stems from an arbitrary file read issue in applications using the libvips library for image processing. Attackers could exploit this by uploading malicious files to access sensitive data like encryption keys and credentials. This would allow them to escalate attacks into full system compromise. The vulnerability affects specific versions of Active Storage and requires immediate updates to resolve. Affected users should upgrade to versions 7.2.3.2, 8.0.5.1, or 8.1.3.1 and ensure libvips is updated to at least version 8.13.