CVE-2026-66066
Description
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
activestorageRubyGems | < 7.2.3.2 | 7.2.3.2 |
activestorageRubyGems | >= 8.0.0.beta1, < 8.0.5.1 | 8.0.5.1 |
activestorageRubyGems | >= 8.1.0.beta1, < 8.1.3.1 | 8.1.3.1 |
Affected products
14- osv-coords12 versionspkg:apk/chainguard/gitlab-rails-ce-19.0pkg:apk/chainguard/gitlab-rails-ce-fips-18.10pkg:apk/chainguard/gitlab-rails-ce-fips-18.11pkg:apk/chainguard/gitlab-rails-ce-fips-19.0pkg:apk/chainguard/gitlab-rails-ce-fips-19.2pkg:apk/chainguard/pgheropkg:apk/chainguard/gitlab-rails-ce-18.9pkg:apk/chainguard/ruby3.3-rails-8.0pkg:apk/chainguard/gitlab-rails-ce-18.8pkg:apk/chainguard/gitlab-rails-ce-18.11pkg:apk/chainguard/pghero-fipspkg:apk/chainguard/gitlab-rails-ce-18.10
< 19.0.5-r0+ 11 more
- (no CPE)range: < 19.0.5-r0
- (no CPE)range: < 18.10.8-r7
- (no CPE)range: < 18.11.8-r0
- (no CPE)range: < 19.0.4-r9
- (no CPE)range: < 19.2.1-r0
- (no CPE)range: < 3.8.0-r3
- (no CPE)range: < 18.9.8-r7
- (no CPE)range: < 8.0.5.1-r0
- (no CPE)range: < 18.8.11-r4
- (no CPE)range: < 18.11.8-r0
- (no CPE)range: < 3.8.0-r3
- (no CPE)range: < 18.10.8-r6
- Range: <7.2.3.2, <8.0.5.1, <8.1.3.1
- Range: <7.2.3.2, <8.0.5.1, <8.1.3.1
Patches
Vulnerability mechanics
References
14- github.com/advisories/GHSA-xr9x-r78c-5hrmghsaADVISORY
- github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1envdWEB
- github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5nvdWEB
- github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49anvdWEB
- github.com/rails/rails/releases/tag/v7.2.3.2nvdWEB
- github.com/rails/rails/releases/tag/v8.0.5.1nvdWEB
- github.com/rails/rails/releases/tag/v8.1.3.1nvdWEB
- github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrmnvdWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.ymlnvdWEB
- thehackernews.com/2026/07/critical-rails-flaw-could-let.htmlnvdWEB
- www.cve.org/CVERecord/SearchResultsghsaWEB
- www.openwall.com/lists/oss-security/2026/07/29/9nvd
- www.openwall.com/lists/oss-security/2026/08/01/6nvd
- ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066nvd
News mentions
15- Hackers Actively Exploiting Critical Langflow RCE and Rails VulnerabilityCyber Security News · Sep 1, 2026
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 ActivityThe Hacker News · Sep 1, 2026
- Critical Ruby on Rails Vulnerability in Attackers’ CrosshairsSecurityWeek · Aug 31, 2026
- Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!Rapid7 Blog · Aug 28, 2026
- Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026Help Net Security · Aug 9, 2026
- Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)Rapid7 Blog · Aug 3, 2026
- Public PoC Released for Critical Rails Active Storage RCE VulnerabilityCyber Security News · Aug 3, 2026
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- 3rd August – Threat Intelligence ReportCheck Point Research · Aug 3, 2026
- KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Help Net Security · Aug 3, 2026
- Rails patches critical Active Storage flaw with RCE potentialBleepingComputer · Aug 1, 2026
- Ruby on Rails Patches Critical VulnerabilitySecurityWeek · Aug 1, 2026
- KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on RailsRapid7 Blog · Jul 30, 2026
- Critical Rails Flaw Lets Attackers Read Arbitrary Files and Execute Malicious Code RemotelyCyber Security News · Jul 30, 2026
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image UploadsThe Hacker News · Jul 29, 2026