CVE Tools

Ruby on Rails Patches Critical Vulnerability

SecurityWeekBy Ionut Arghire

PatchRuby on Rails

Our summary

Ruby on Rails has issued patches for a severe vulnerability that could enable unauthenticated attackers to execute arbitrary code remotely. The flaw, tracked as CVE-2026-66066 with a CVSS score of 9.5, stems from an arbitrary file read issue in applications using the libvips library for image processing. Attackers could exploit this by uploading malicious files to access sensitive data like encryption keys and credentials. This would allow them to escalate attacks into full system compromise. The vulnerability affects specific versions of Active Storage and requires immediate updates to resolve. Affected users should upgrade to versions 7.2.3.2, 8.0.5.1, or 8.1.3.1 and ensure libvips is updated to at least version 8.13.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store