CVE Tools

CVE-2026-66066

Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing

No known exploitation. EPSS puts it in the 81st percentile. No fix published yet.

Published Updated Sources: CVE.org, NVD

What to do

No fixed build or workaround is published yet. Limit exposure and watch for a patch.

Steps

Written by AI from the record
  1. Check whether your Rails app uses Active Storage for image uploads and whether the app is configured to use libvips for variant processing.
  2. Check your Rails version and record it for your IT/vendor (the fix version is not confirmed in the provided findings).
  3. If you use Active Storage with untrusted image uploads, temporarily restrict or block image uploads from untrusted users until you can confirm an approved fix/upgrade.
  4. Contact your Rails/hosting vendor or IT team with CVE-2026-66066 and ask for an upgrade path or hotfix for your specific Rails version.
  5. Review application logs for suspicious image upload attempts and errors around image processing, and watch for signs of unauthorized access after uploads.

What it is

From the CVE record

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

In plain language

Written by AI from the record

CVE-2026-66066 is a Rails issue where a bad image upload could let an attacker read sensitive files—and possibly run code—if your app uses Active Storage with image processing; small businesses should act urgently to confirm your Rails version and image-processing setup.

In Rails (Action Pack / Active Storage variant processing), crafted uploads can trigger unsafe libvips operations for untrusted content (CWE-1188), potentially leading to arbitrary file read and, depending on exposed credentials, remote code execution; no public patch guidance was available in the provided findings.

If you're affected

  • Stolen app secrets
  • Service takeover via code execution
  • Credential theft
  • Operational disruption

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS81st
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

2.1% chance of exploitation activity in the next 30 days, which ranks it in the 81st percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Attention now

Rising.

Lifecycle

15 events over 56 days, from the signal feeds we watch.

  1. EPSS band changemoderate → lowepss band change
  2. Record updated
  3. EPSS band changelow → moderateepss band change
  4. Analysis publishedTwo Parsers, One File, Zero Agreement: The Attack Surface Behind CVE-2026-66066
  5. Record updated
  6. Record updated

Affected products

Technical detail

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Rails, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store