< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-29T23:40:00+05:30

Critical Ruby on Rails Active Storage Vulnerability (CVE-2026-66066) Allows Unauthenticated File Read via Image Uploads

A critical Ruby on Rails Active Storage vulnerability (CVE-2026-66066) allows unauthenticated attackers to read server files via crafted image uploads, exposing sensitive secrets like API tokens and database credentials. Affected versions require immediate upgrades to patched releases and libvips updates to mitigate risks of remote code execution and lateral movement.

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.

Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

Read original article

*** END OF TRANSMISSION ***