CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads
ID: 3085e85c-8efc-5f22-8fbd-d8d7b01da392
STIX ID: report--3085e85c-8efc-5f22-8fbd-d8d7b01da392
Feed Name: SOC Prime Blog
Ruby on Rails Active Storage contains a critical arbitrary file-read vulnerability (CVE-2026-66066, CVSS 9.5) when applications use libvips for image processing and accept untrusted uploads; crafted images can trigger unsafe libvips operations to disclose files readable by the Rails process—potentially exposing secret_key_base, master keys, database and cloud credentials, and third-party tokens, which may lead to session forgery, RCE, or lateral movement. The advisory lists affected Rails releases, requires upgrading Rails to 7.2.3.2/8.0.5.1/8.1.3.1 (or later) and libvips to 8.13+/ruby-vips 2.2.1+, describes temporary mitigations, and urges rotating all secrets and reviewing logs for suspicious upload activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
