CVE Tools
Back to feed
PoC public Active Storage rce libvips Ruby on Rails web-app

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

Help Net Security·By Zeljka Zorz··4 min read
CVE Tools coverage

A critical vulnerability (CVE-2026-66066) in Ruby on Rails has been patched after researchers identified it could allow attackers to read sensitive server files and possibly achieve full remote control. Dubbed 'KindaRails2Shell', the flaw exploits weaknesses in how the framework's Active Storage component processes uploaded image files through the libvips library. Attackers can bypass security measures by uploading maliciously crafted non-image files disguised as images, enabling unauthorized data access and potential system compromise. The issue affects specific versions of Rails 7.x and 8.x that use the default vips image processor. Users are strongly advised to upgrade to the newly released secure versions—7.2.3.2, 8.0.5.1, or 8.1.3.1—and rotate all relevant credentials as a precaution.