CVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Description
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
In plain language
AI Act nowCVE-2026-66066 is a Rails issue where a bad image upload could let an attacker read sensitive files—and possibly run code—if your app uses Active Storage with image processing; small businesses should act urgently to confirm your Rails version and image-processing setup.
In Rails (Action Pack / Active Storage variant processing), crafted uploads can trigger unsafe libvips operations for untrusted content (CWE-1188), potentially leading to arbitrary file read and, depending on exposed credentials, remote code execution; no public patch guidance was available in the provided findings.
What to do now
- Check whether your Rails app uses Active Storage for image uploads and whether the app is configured to use libvips for variant processing.
- Check your Rails version and record it for your IT/vendor (the fix version is not confirmed in the provided findings).
- If you use Active Storage with untrusted image uploads, temporarily restrict or block image uploads from untrusted users until you can confirm an approved fix/upgrade.
- Contact your Rails/hosting vendor or IT team with CVE-2026-66066 and ask for an upgrade path or hotfix for your specific Rails version.
- Review application logs for suspicious image upload attempts and errors around image processing, and watch for signs of unauthorized access after uploads.
Weaknesses
Affected Products
Exploitability
References
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activityen·The Hacker News· Exploited Langflow rce
- Critical Ruby on Rails Vulnerability in Attackers’ Crosshairsen-us·SecurityWeek· Exploited Ruby on Rails rce
- Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026en-us·Help Net Security· Roundup web-app
- В Ruby on Rails устранили критическую RCE-уязвимостьru-ru·Хакер (xakep.ru)· PoC Ruby on Rails rce
- Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)en·Rapid7 Blog· Advisory Ruby on Rails Active Storage web-app
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacksen·The Hacker News· Exploited Coldcard Wallet Laundry Bear
- 3rd August – Threat Intelligence Reporten-us·Check Point Research· Incident Minnesota Water Systems data-breach
- KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)en-us·Help Net Security· PoC Active Storage rce
- Rails patches critical Active Storage flaw with RCE potentialen-us·BleepingComputer· PoC Active Storage rce
- Ruby on Rails Patches Critical Vulnerabilityen-us·SecurityWeek· Patch Ruby on Rails rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-66066 and every CVE in our database. Create a free account — no credit card required.
Create Free Account