active-storage

Tag

Cards List
#active-storage

KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)

Lobsters Hottest · 2026-07-30 Cached

A critical remote code execution vulnerability (CVE-2026-66066) has been discovered in Ruby on Rails' Active Storage when using the default Vips image processor, affecting Rails 7.x and 8.x default configurations. Patches have been released and immediate upgrading is recommended.

0 favorites 0 likes
← Back to home

Submit Feedback