logo

Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing

ID: df9f7957-8d35-5f1b-858f-c35d9d93a320

STIX ID: report--df9f7957-8d35-5f1b-858f-c35d9d93a320

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Pierluigi Paganini

...
...

Ruby on Rails patched CVE-2026-66066, a critical (CVSS 9.5) Active Storage vulnerability that can let unauthenticated attackers upload crafted images that trigger unsafe libvips operations to read arbitrary files (including environment secrets) and potentially enable remote code execution; remediation is to upgrade Active Storage, update libvips to 8.13+, and rotate any exposed secrets such as secret_key_base.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.