Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5589 articles · 220728 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-66066KEVEXPLOITEDPATCHED
rubygems · activestorage

Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing

Description

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Affected Products

VendorProductVersions
rubygemsactivestorage< 7.2.3.2, >= 8.0.0.beta1, < 8.0.5.1, >= 8.1.0.beta1, < 8.1.3.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmlicense metric toolcert_advisory90%
rubygemsactivestorageGHSA85%

References

  • https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm(x_refsource_CONFIRM)
  • https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e(x_refsource_MISC)
  • https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5(x_refsource_MISC)
  • https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v7.2.3.2(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v8.0.5.1(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v8.1.3.1(x_refsource_MISC)
  • https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.yml(x_refsource_MISC)
  • https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html(x_refsource_MISC)

Related News (25 articles)

Tier E
Hacker News17d ago
Government Rails Site Hit Hours After CVE Patch
→ No new info (linked only)
Tier D
The Hacker News21d ago
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
→ No new info (linked only)
Tier D
SecurityWeek22d ago
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
→ No new info (linked only)
Tier C
Rapid7 Blog24d ago
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
→ No new info (linked only)
Tier B
BSI Advisories32d ago
[NEU] [hoch] IBM License Metric Tool: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Help Net Security44d ago
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
→ No new info (linked only)
Tier E
Hacker News47d ago
Zero-Day to Zero Doubt: AI-Powered CVE Forensics in an Afternoon
→ No new info (linked only)
Tier D
CSO Online48d ago
Ruby on Rails critical bug puts every image upload under scrutiny
→ No new info (linked only)
Tier C
Rapid7 Blog49d ago
Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
→ No new info (linked only)
Tier D
The Hacker News49d ago
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
→ No new info (linked only)
Tier D
Help Net Security50d ago
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
→ No new info (linked only)
Tier B
CERT-FR50d ago
Bulletin d'actualité CERTFR-2026-ACT-033 (03 août 2026)
→ No new info (linked only)
Tier D
BleepingComputer51d ago
Rails patches critical Active Storage flaw with RCE potential
→ No new info (linked only)
Tier D
SecurityWeek52d ago
Ruby on Rails Patches Critical Vulnerability
→ No new info (linked only)
Tier D
Heise Security52d ago
Schlüsselklau bei Ruby on Rails – Kritische Lücke mit präparierten Bildern
→ No new info (linked only)
Tier C
oss-security52d ago
Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
→ No new info (linked only)
Tier B
CCCS Canada52d ago
Rails security advisory (AV26-767)
→ No new info (linked only)
Tier C
VulDB53d ago
CVE-2026-66066 | Rails prior 7.2.3.2/8.0.5.1/8.1.3.1 Active Storage unrestricted upload
→ No new info (linked only)
Tier C
Rapid7 Blog53d ago
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
→ No new info (linked only)
Tier E
Lobsters Security53d ago
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)
→ No new info (linked only)
Tier E
Reddit r/netsec53d ago
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
→ No new info (linked only)
Tier B
BSI Advisories54d ago
[NEU] [hoch] Ruby on Rails: Schwachstelle ermöglicht Offenlegung von Informationen
→ No new info (linked only)
Tier B
CERT-FR54d ago
Vulnérabilité dans Ruby on Rails activestorage (30 juillet 2026)
→ No new info (linked only)
Tier C
oss-security54d ago
Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
→ No new info (linked only)
Tier D
The Hacker News54d ago
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
activestorage@7.2.3.2activestorage@8.0.5.1activestorage@8.1.3.1
CWECWE-1188
PublishedJul 30, 2026
Tags
GHSA-xr9x-r78c-5hrmrubygems
Trending Score13
Source articles25
Independent15
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-44163
fluent-plugin-opentelemetry: Denial of Service (DoS) via Large Payloads and Decompression Bombs in `in_opentelemetry`
Trending: 15
HIGHCVE-2026-50276
dd-trace-rb: Improper parsing of W3C baggage headers may lead to DoS
Trending: 14
MEDIUMCVE-2026-54171
Excon: redact additional sensitive/risky headers when following redirects
Trending: 10
LOWCVE-2026-44162
fluent-plugin-s3: Denial of Service (DoS) via Decompression Bomb in `in_s3`
Trending: 6
MEDIUMCVE-2026-53769
Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policy
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Added to CISA KEV
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Actively Exploited
Aug 5, 2026
Patch Available
Aug 5, 2026