CVE-2026-66066
Published Jul 30, 2026
Last updated 5 days ago
AI description
CVE-2026-66066, also known as "KindaRails2Shell," is an arbitrary file read vulnerability affecting Ruby on Rails Active Storage variant processing. This flaw stems from an insecure default in how Active Storage handles image variants through the `libvips` library. Specifically, Active Storage fails to disable certain `libvips` operations, termed "unfuzzed," which are not hardened against malicious input and are unsafe when processing untrusted content. This oversight allows an attacker to upload a specially crafted file, triggering these unsafe processing paths within `libvips`. Successful exploitation of CVE-2026-66066 can lead to the disclosure of arbitrary files accessible to the Rails application process, including sensitive data like process environment variables, `secret_key_base`, and other application secrets. The exposure of these secrets can subsequently enable further compromise, such as remote code execution or lateral movement within connected systems. An application is vulnerable if it uses `libvips` for Active Storage image processing (the default for Rails 7.0+), accepts image uploads from untrusted users, and generates variants from those uploads.
- Description
- Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
- Source
- security-advisories@github.com
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 9.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-1188
- Hype score
- Not currently trending
Langflow と Rails の脆弱性を攻撃する脅威アクターたち:CVE-2026-0768/66066 を悪用 https://t.co/OpkoXooTIW この記事は、Langflow と Ruby on Rails の危険な脆弱性 CVE-2026-0768/CVE-2026-66066
@iototsecnews
9 Sept 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-66066, 'KindaRails2Shell', explota ActiveStorage en Rails 8+ con CVSS 9.5. Fue comprometida en menos de 8 horas tras el parche. ¡Actualiza ya! https://t.co/njNL4XxWuW
@renodevv
5 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-66066 hit a state government Rails site seven hours after disclosure. The flaw sits in ActiveStorage variant processing on Rails 8 and newer. A malformed BMP file triggers arbitrary file read and remote code execution. Public PoC landed on GitHub at 2026-07-29 21:47:30
@SecureChap
5 Sept 2026
91 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 AI workflows and Rails applications are under active attack. Threat actors are exploiting CVE-2026-0768 in Langflow and CVE-2026-66066 in Ruby on Rails. The Langflow flaw can enable unauthenticated Python execution as root. The Rails issue abuses image-processing behaviour
@Certix_com
3 Sept 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical Ruby on Rails Vulnerability Under Active Attack | CVE-2026-66066 https://t.co/o0dtPiGRKK #rubyonrails #security #infosec
@HOCupdate
2 Sept 2026
287 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Active exploitation of CVE-2026-66066 (KindaRails2Shell) is underway. A malicious image upload on Ruby on Rails (CVSS 9.5) can lead to arbitrary file read, credential theft and RCE. Patch immediately. #RubyOnRails #InfoSec #CVE https://t.co/ByAAow2yFw
@CyberWorldOps
1 Sept 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Investigadores de VulnCheck detectaron campañas activas que explotan las vulnerabilidades CVE-2026-0768 (Langflow) y CVE-2026-66066 (KindaRails2Shell en Ruby on Rails). Los ciberdelincuentes aprovechan estos fallos para ejecutar código arbitrario como root, exfiltrar claves de
@tpx_Security
1 Sept 2026
110 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Two actively exploited bugs, one shared risk: credential exposure. 🔹 CVE-2026-0768: unauthenticated RCE in Langflow (Python) 🔹 CVE-2026-66066: Rails Active Storage flaw exposing files & secrets Keys/tokens stolen now can stay useful post-patch. Patch, hunt, rotate.
@socradar
1 Sept 2026
566 Impressions
2 Retweets
4 Likes
1 Bookmark
1 Reply
0 Quotes
On August 31, 2026, VulnCheck reported active exploitation of CVE-2026-66066. When Rails Active Storage processes an untrusted file with libvips, attackers may read server files; exposed application secrets could then enable remote code execution or lateral movement.
@Securehup
1 Sept 2026
98 Impressions
0 Retweets
1 Like
1 Bookmark
1 Reply
0 Quotes
🐦 🚨 Actively exploited today: PaperCut NG/MF flaws now in CISA KEV (data theft), Langflow CVE-2026-0768 (CVSS 9.8) + Rails CVE-2026-66066 under mass exploitation, and JFrog Artifactory auth-bypass CVE-2026-82329 hit in-the-wild. Patch now. #infosec #CVE #0day
@ita_ipo
1 Sept 2026
105 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-0768 and CVE-2026-66066: Active Exploitation of Critical Langflow and … "VulnCheck has published findings confirming that threat actors are actively…" 🔗 https://t.co/tIiok3E8Di #CyberSecurity #ThreatIntel #sigmarule #kqldetection #threathun
@SecurityAr58409
1 Sept 2026
41 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Langflow ve Ruby on Rails Açıkları Aktif İstismarda CVE-2026-0768 (CVSS 9.8) ve CVE-2026-66066 (CVSS 9.5) saldırganların sistemlere sızıp kimlik bilgilerini toplamasına ve uzaktan kod çalıştırmasına imkan veriyor. VulnCheck, saatler içinde 360 istismar tesp
@KubbeSiber
1 Sept 2026
46 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Active credential harvesting & remote code execution stemming from CVE-2026-0768 and CVE-2026-66066 flaws are targeting Langflow & Ruby on Rails users as AI dev platforms become preferred attack vectors. Exposed Rails instances, image upload vulnerabilities via libvips, a
@dailytechonx
1 Sept 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🎯 KindaRails2Shell: critical Ruby on Rails flaw allows file read and full server takeover (CVE-2026-66066) A critical vulnerability in Ruby on Rails (CVE-2026-66066) lets attackers read sensitive files off servers and in some cases take full remote control. Rails powers a hug
@XQOPTRX
10 Aug 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🖼️ 이미지 업로드만으로 서버 파일이 노출될 수 있습니다 Ruby on Rails Active Storage에서 CVE-2026-66066 (CVSS 9.5) 취약점이 공개됐습니다. 공격자는 조작된 이미지를 업로드해 Rails 애플리케이션이 접근 가능한 서
@CriminalIP_KR
7 Aug 2026
87 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ruby on Rails'te CVSS 9.5 Kritik Açık, Dosya Okuma RCE'ye Kadar Uzanıyor Ruby on Rails'in Active Storage bileşenindeki bir açık, saldırganların sunucudan gizli anahtarları çalıp uzaktan kod çalıştırmasına kadar uzanan bir saldırı zincirine kapı açıyor! •
@BTHaberler
4 Aug 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Ruby on Rails patched CVE-2026-66066, an Active Storage flaw affecting apps that process untrusted images with libvips. Exposed files could leak secrets and enable deeper compromise. Source: Gridinsoft #RubyOnRails #CVE #AppSec
@XQOPTRX
2 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【緊急】Ruby on Rails脆弱性「KindaRails2Shell」CVE-2026-66066、急ぐ3つの対策 https://t.co/YG65brjNr7 #IT #Security #cybersecurity
@Teeeda_worker
2 Aug 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Critical Ruby on Rails Flaw Can Expose Server Files Security researchers have published technical details for CVE-2026-66066, nicknamed KindaRails2Shell, affecting Ruby on Rails applications using vulnerable Active Storage and libvips configurations. A crafted upload may
@XQOPTRX
1 Aug 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-66066 Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips ope… https://t.co/moRI82g9Nu ----- Traducción: CVE-2026-66066 Act… https://t.co/utmtNg
@infoflowcloud
30 Jul 2026
57 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
GitHub - Zer0SumGam3/CVE-2026-66066-POC: PoC for CVE-2026-66066 in Ruby on Rails · GitHub https://t.co/lRI8cfUsPk
@akaclandestine
30 Jul 2026
3063 Impressions
7 Retweets
27 Likes
8 Bookmarks
0 Replies
0 Quotes