Rails Active Storage RCE Vulnerability: Critical PoC Released
ID: 05f6247d-f85a-5d48-8b38-8e996bf14529
STIX ID: report--05f6247d-f85a-5d48-8b38-8e996bf14529
Feed Name: CyberNexora News
### Executive summary CVE-2026-66066 (KindaRails2Shell) is a critical vulnerability in Rails Active Storage when processed with libvips that permits unauthenticated attackers to upload specially crafted images to disclose server-side secrets (including secret_key_base) and potentially escalate to remote code execution; public proof-of-concept code and a proposed Metasploit module increase the risk of active exploitation, so immediate patching, credential rotation, and log review are strongly recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
