CVE-2026-66066
Published Jul 30, 2026
Last updated 14 hours ago
AI description
CVE-2026-66066, also known as "KindaRails2Shell," is an arbitrary file read vulnerability affecting Ruby on Rails Active Storage variant processing. This flaw stems from an insecure default in how Active Storage handles image variants through the `libvips` library. Specifically, Active Storage fails to disable certain `libvips` operations, termed "unfuzzed," which are not hardened against malicious input and are unsafe when processing untrusted content. This oversight allows an attacker to upload a specially crafted file, triggering these unsafe processing paths within `libvips`. Successful exploitation of CVE-2026-66066 can lead to the disclosure of arbitrary files accessible to the Rails application process, including sensitive data like process environment variables, `secret_key_base`, and other application secrets. The exposure of these secrets can subsequently enable further compromise, such as remote code execution or lateral movement within connected systems. An application is vulnerable if it uses `libvips` for Active Storage image processing (the default for Rails 7.0+), accepts image uploads from untrusted users, and generates variants from those uploads.
- Description
- Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
- Source
- security-advisories@github.com
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 9.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-1188
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
6
⚠️ Critical Ruby on Rails Flaw Can Expose Server Files Security researchers have published technical details for CVE-2026-66066, nicknamed KindaRails2Shell, affecting Ruby on Rails applications using vulnerable Active Storage and libvips configurations. A crafted upload may
@XQOPTRX
1 Aug 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-66066 Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips ope… https://t.co/moRI82g9Nu ----- Traducción: CVE-2026-66066 Act… https://t.co/utmtNg
@infoflowcloud
30 Jul 2026
57 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
GitHub - Zer0SumGam3/CVE-2026-66066-POC: PoC for CVE-2026-66066 in Ruby on Rails · GitHub https://t.co/lRI8cfUsPk
@akaclandestine
30 Jul 2026
3063 Impressions
7 Retweets
27 Likes
8 Bookmarks
0 Replies
0 Quotes