CVE detail
CVE-2026-66066
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.3 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 16
- within the 30d window
- Peak daily
- 11
- highest bucket
Evidence
Source links by recency
16 source links · newest first
Linked URL: https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432 | Posted by lobo_tuerto | 3 points | 0 comments
communitynews.ycombinator.comJul 31, 2026, 2:53 PMLinked URL: https://github.com/rails/rails-forensics-CVE-2026-66066 | Posted by ezekg | 3 points | 0 comments
communitynews.ycombinator.comJul 31, 2026, 2:16 PMNo excerpt available.
Exploitethiack.comJul 30, 2026, 7:18 PM- http://www.openwall.com/lists/oss-security/2026/07/29/9www.openwall.com
No excerpt available.
Exploitwww.openwall.comJul 30, 2026, 7:18 PM - https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.ymlgithub.com
No excerpt available.
Exploitgithub.comJul 30, 2026, 7:18 PM No excerpt available.
Exploitgithub.comJul 30, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJul 30, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJul 30, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJul 30, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJul 30, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJul 30, 2026, 7:18 PMNo excerpt available.
Exploitgithub.comJul 30, 2026, 7:18 PMOverview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of
vendorwww.rapid7.comJul 30, 2026, 4:11 PM- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsThe Hacker News
d let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,
newsthehackernews.comJul 29, 2026, 6:10 PM Linked URL: https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432 | Posted by baggy_trough | 5 points | 0 comments
communitynews.ycombinator.comJul 29, 2026, 3:58 PMLinked URL: https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066 | Posted by tenderlove | 6 points | 0 comments
communitynews.ycombinator.comJul 29, 2026, 3:42 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-67208CVSS 9.3 · Critical
Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 d…
- CVE-2026-65881CVSS 7.5 · High
Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read…
- CVE-2026-9680CVSS 5.8 · Medium
Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on a…
- CVE-2026-47668CVSS 10.0 · Critical
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the…
- CVE-2026-55708CVSS 3.1 · Low
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already co…
- CVE-2026-47393CVSS 9.8 · Critical
PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) tha…