CVE-2026-66066

Published Jul 30, 2026

Last updated 5 days ago

CVSS critical 9.5
Rails
Active Storage
Action Pack

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-66066, also known as "KindaRails2Shell," is an arbitrary file read vulnerability affecting Ruby on Rails Active Storage variant processing. This flaw stems from an insecure default in how Active Storage handles image variants through the `libvips` library. Specifically, Active Storage fails to disable certain `libvips` operations, termed "unfuzzed," which are not hardened against malicious input and are unsafe when processing untrusted content. This oversight allows an attacker to upload a specially crafted file, triggering these unsafe processing paths within `libvips`. Successful exploitation of CVE-2026-66066 can lead to the disclosure of arbitrary files accessible to the Rails application process, including sensitive data like process environment variables, `secret_key_base`, and other application secrets. The exposure of these secrets can subsequently enable further compromise, such as remote code execution or lateral movement within connected systems. An application is vulnerable if it uses `libvips` for Active Storage image processing (the default for Rails 7.0+), accepts image uploads from untrusted users, and generates variants from those uploads.

Description
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-1188

Social media

Hype score
Not currently trending
  1. Langflow と Rails の脆弱性を攻撃する脅威アクターたち:CVE-2026-0768/66066 を悪用 https://t.co/OpkoXooTIW この記事は、Langflow と Ruby on Rails の危険な脆弱性 CVE-2026-0768/CVE-2026-66066

    @iototsecnews

    9 Sept 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2026-66066, 'KindaRails2Shell', explota ActiveStorage en Rails 8+ con CVSS 9.5. Fue comprometida en menos de 8 horas tras el parche. ¡Actualiza ya! https://t.co/njNL4XxWuW

    @renodevv

    5 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2026-66066 hit a state government Rails site seven hours after disclosure. The flaw sits in ActiveStorage variant processing on Rails 8 and newer. A malformed BMP file triggers arbitrary file read and remote code execution. Public PoC landed on GitHub at 2026-07-29 21:47:30

    @SecureChap

    5 Sept 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔥 AI workflows and Rails applications are under active attack. Threat actors are exploiting CVE-2026-0768 in Langflow and CVE-2026-66066 in Ruby on Rails. The Langflow flaw can enable unauthenticated Python execution as root. The Rails issue abuses image-processing behaviour

    @Certix_com

    3 Sept 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Critical Ruby on Rails Vulnerability Under Active Attack | CVE-2026-66066 https://t.co/o0dtPiGRKK #rubyonrails #security #infosec

    @HOCupdate

    2 Sept 2026

    287 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Active exploitation of CVE-2026-66066 (KindaRails2Shell) is underway. A malicious image upload on Ruby on Rails (CVSS 9.5) can lead to arbitrary file read, credential theft and RCE. Patch immediately. #RubyOnRails #InfoSec #CVE https://t.co/ByAAow2yFw

    @CyberWorldOps

    1 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Investigadores de VulnCheck detectaron campañas activas que explotan las vulnerabilidades CVE-2026-0768 (Langflow) y CVE-2026-66066 (KindaRails2Shell en Ruby on Rails). Los ciberdelincuentes aprovechan estos fallos para ejecutar código arbitrario como root, exfiltrar claves de

    @tpx_Security

    1 Sept 2026

    110 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 Two actively exploited bugs, one shared risk: credential exposure. 🔹 CVE-2026-0768: unauthenticated RCE in Langflow (Python) 🔹 CVE-2026-66066: Rails Active Storage flaw exposing files & secrets Keys/tokens stolen now can stay useful post-patch. Patch, hunt, rotate.

    @socradar

    1 Sept 2026

    566 Impressions

    2 Retweets

    4 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  9. On August 31, 2026, VulnCheck reported active exploitation of CVE-2026-66066. When Rails Active Storage processes an untrusted file with libvips, attackers may read server files; exposed application secrets could then enable remote code execution or lateral movement.

    @Securehup

    1 Sept 2026

    98 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  10. 🐦 🚨 Actively exploited today: PaperCut NG/MF flaws now in CISA KEV (data theft), Langflow CVE-2026-0768 (CVSS 9.8) + Rails CVE-2026-66066 under mass exploitation, and JFrog Artifactory auth-bypass CVE-2026-82329 hit in-the-wild. Patch now. #infosec #CVE #0day

    @ita_ipo

    1 Sept 2026

    105 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🔒 #CyberSecurity CVE-2026-0768 and CVE-2026-66066: Active Exploitation of Critical Langflow and … "VulnCheck has published findings confirming that threat actors are actively…" 🔗 https://t.co/tIiok3E8Di #CyberSecurity #ThreatIntel #sigmarule #kqldetection #threathun

    @SecurityAr58409

    1 Sept 2026

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 Langflow ve Ruby on Rails Açıkları Aktif İstismarda CVE-2026-0768 (CVSS 9.8) ve CVE-2026-66066 (CVSS 9.5) saldırganların sistemlere sızıp kimlik bilgilerini toplamasına ve uzaktan kod çalıştırmasına imkan veriyor. VulnCheck, saatler içinde 360 istismar tesp

    @KubbeSiber

    1 Sept 2026

    46 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Active credential harvesting & remote code execution stemming from CVE-2026-0768 and CVE-2026-66066 flaws are targeting Langflow & Ruby on Rails users as AI dev platforms become preferred attack vectors. Exposed Rails instances, image upload vulnerabilities via libvips, a

    @dailytechonx

    1 Sept 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🎯 KindaRails2Shell: critical Ruby on Rails flaw allows file read and full server takeover (CVE-2026-66066) A critical vulnerability in Ruby on Rails (CVE-2026-66066) lets attackers read sensitive files off servers and in some cases take full remote control. Rails powers a hug

    @XQOPTRX

    10 Aug 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🖼️ 이미지 업로드만으로 서버 파일이 노출될 수 있습니다​ Ruby on Rails Active Storage에서 CVE-2026-66066 (CVSS 9.5) 취약점이 공개됐습니다.​ 공격자는 조작된 이미지를 업로드해 Rails 애플리케이션이 접근 가능한 서

    @CriminalIP_KR

    7 Aug 2026

    87 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Ruby on Rails'te CVSS 9.5 Kritik Açık, Dosya Okuma RCE'ye Kadar Uzanıyor Ruby on Rails'in Active Storage bileşenindeki bir açık, saldırganların sunucudan gizli anahtarları çalıp uzaktan kod çalıştırmasına kadar uzanan bir saldırı zincirine kapı açıyor! •

    @BTHaberler

    4 Aug 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 Ruby on Rails patched CVE-2026-66066, an Active Storage flaw affecting apps that process untrusted images with libvips. Exposed files could leak secrets and enable deeper compromise. Source: Gridinsoft #RubyOnRails #CVE #AppSec

    @XQOPTRX

    2 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 【緊急】Ruby on Rails脆弱性「KindaRails2Shell」CVE-2026-66066、急ぐ3つの対策 https://t.co/YG65brjNr7 #IT #Security #cybersecurity

    @Teeeda_worker

    2 Aug 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. ⚠️ Critical Ruby on Rails Flaw Can Expose Server Files Security researchers have published technical details for CVE-2026-66066, nicknamed KindaRails2Shell, affecting Ruby on Rails applications using vulnerable Active Storage and libvips configurations. A crafted upload may

    @XQOPTRX

    1 Aug 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨*CVE* CVE-2026-66066 Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips ope… https://t.co/moRI82g9Nu ----- Traducción: CVE-2026-66066 Act… https://t.co/utmtNg

    @infoflowcloud

    30 Jul 2026

    57 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  21. GitHub - Zer0SumGam3/CVE-2026-66066-POC: PoC for CVE-2026-66066 in Ruby on Rails · GitHub https://t.co/lRI8cfUsPk

    @akaclandestine

    30 Jul 2026

    3063 Impressions

    7 Retweets

    27 Likes

    8 Bookmarks

    0 Replies

    0 Quotes