CVE-2026-66066

Published Jul 30, 2026

Last updated 14 hours ago

CVSS critical 9.5
Rails
Active Storage
Action Pack

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-66066, also known as "KindaRails2Shell," is an arbitrary file read vulnerability affecting Ruby on Rails Active Storage variant processing. This flaw stems from an insecure default in how Active Storage handles image variants through the `libvips` library. Specifically, Active Storage fails to disable certain `libvips` operations, termed "unfuzzed," which are not hardened against malicious input and are unsafe when processing untrusted content. This oversight allows an attacker to upload a specially crafted file, triggering these unsafe processing paths within `libvips`. Successful exploitation of CVE-2026-66066 can lead to the disclosure of arbitrary files accessible to the Rails application process, including sensitive data like process environment variables, `secret_key_base`, and other application secrets. The exposure of these secrets can subsequently enable further compromise, such as remote code execution or lateral movement within connected systems. An application is vulnerable if it uses `libvips` for Active Storage image processing (the default for Rails 7.0+), accepts image uploads from untrusted users, and generates variants from those uploads.

Description
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
Source
security-advisories@github.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-1188

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

6