Skip to main content

Rails patches critical Active Storage flaw with RCE potential

0
Critical
Vulnerabilityremoterce
Published: 08/01/2026 (08/01/2026, 14:20:30 UTC)
Source: Bleeping Computer

Description

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

Affected software

Affected versions
<7.2.3.2>=8.0.0 <8.0.5.1>=8.1.0 <8.1.3.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/01/2026, 14:48:21 UTC

Technical Analysis

CVE-2026-66066 is a critical vulnerability in the Rails Active Storage framework that permits unauthenticated attackers to upload specially crafted images processed by libvips, enabling arbitrary file read on the server and potential escalation to remote code execution. The attack requires that the server accepts image uploads from untrusted users and uses libvips prior to version 8.13. Exploitation can expose sensitive files such as the process environment containing secret_key_base and credentials, which attackers can leverage to forge session cookies and manipulate serialized data, leading to full RCE. The vulnerability affects Active Storage versions before 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1; Rails 6.x is affected only if Active Storage is configured outside defaults. Mitigations include upgrading Rails to fixed versions, upgrading libvips to 8.13 or later, rotating all secrets, and optionally disabling vulnerable libvips functionality. ImageMagick users are not impacted. The Rails team initially delayed full disclosure to allow patching but released full details after public proof-of-concept exploits appeared. Akamai has published WAF rules to mitigate attacks.

Potential Impact

Successful exploitation allows unauthenticated attackers to read arbitrary files on the server, including sensitive application secrets such as secret_key_base and database credentials. With these secrets, attackers can forge session cookies, sign global IDs, and manipulate serialized data, resulting in full remote code execution on the underlying server. This compromises the confidentiality, integrity, and availability of the affected Rails application and its data.

Mitigation Recommendations

A fix is available by upgrading Rails Active Storage to versions 7.2.3.2 or later, 8.0.5.1 or later, or 8.1.3.1 or later. Additionally, upgrade libvips to version 8.13 or newer. For systems running libvips 8.13 or later, administrators can temporarily disable the vulnerable functionality by setting the VIPS_BLOCK_UNTRUSTED environment variable or calling Vips.block_untrusted(true) in ruby-vips 2.2.1 or newer. Rotate the secret_key_base, database credentials, Active Storage service credentials, and any other secrets accessible to the application process after patching. No workaround exists for libvips versions prior to 8.13. ImageMagick users are not affected by this vulnerability. Web application firewall (WAF) protections are available from Akamai and may provide additional defense but should not replace patching.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"stated","classifier":"rss-v2"}

Threat ID: 6a6e0723bf32cb7a34e2773c

Added to database: 08/01/2026, 14:48:03 UTC

Last enriched: 08/01/2026, 14:48:21 UTC

Last updated: 09/10/2026, 08:53:06 UTC

Views: 99

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses