CVE Tools
Back to feed
Exploited in the wild Ruby on Rails rce web-app

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

VulnCheck has reported active exploitation of CVE-2026-66066, a critical remote code execution vulnerability in Ruby on Rails affecting applications that use libvips for image processing in Active Storage. Dubbed "KindaRails2Shell," this flaw allows unauthenticated attackers to read arbitrary files and potentially execute code by abusing discrepancies between how different libraries interpret file types. Although patches were released in late July, the vector remains severe with a CVSS score of 9.5, and approximately 7,000 exposed instances were identified earlier this month.