CVE-2026-66066
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
No known exploitation. EPSS puts it in the 81st percentile. No fix published yet.
What to do
No fixed build or workaround is published yet. Limit exposure and watch for a patch.
Steps
Written by AI from the record- Check whether your Rails app uses Active Storage for image uploads and whether the app is configured to use libvips for variant processing.
- Check your Rails version and record it for your IT/vendor (the fix version is not confirmed in the provided findings).
- If you use Active Storage with untrusted image uploads, temporarily restrict or block image uploads from untrusted users until you can confirm an approved fix/upgrade.
- Contact your Rails/hosting vendor or IT team with CVE-2026-66066 and ask for an upgrade path or hotfix for your specific Rails version.
- Review application logs for suspicious image upload attempts and errors around image processing, and watch for signs of unauthorized access after uploads.
What it is
From the CVE record
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
In plain language
Written by AI from the recordCVE-2026-66066 is a Rails issue where a bad image upload could let an attacker read sensitive files—and possibly run code—if your app uses Active Storage with image processing; small businesses should act urgently to confirm your Rails version and image-processing setup.
In Rails (Action Pack / Active Storage variant processing), crafted uploads can trigger unsafe libvips operations for untrusted content (CWE-1188), potentially leading to arbitrary file read and, depending on exposed credentials, remote code execution; no public patch guidance was available in the provided findings.
If you're affected
- Stolen app secrets
- Service takeover via code execution
- Credential theft
- Operational disruption
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
2.1% chance of exploitation activity in the next 30 days, which ranks it in the 81st percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
- Attention now
Rising.
Lifecycle
15 events over 56 days, from the signal feeds we watch.
- EPSS band changemoderate → lowepss band change
- Record updated
- EPSS band changelow → moderateepss band change
- Analysis publishedTwo Parsers, One File, Zero Agreement: The Attack Surface Behind CVE-2026-66066
- Record updated
- Record updated
Affected products
Technical detail
Weaknesses
Sources
References in the record
- github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm
- github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e
- github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5
And 10 more references. See all after sign-in
In the news
All news- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
- Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
- Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
- В Ruby on Rails устранили критическую RCE-уязвимость
- Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
- 3rd August – Threat Intelligence Report
- KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
- Rails patches critical Active Storage flaw with RCE potential
- Ruby on Rails Patches Critical Vulnerability
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Rails, not every advisory.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI