Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2981 articles · 185100 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-66066PATCHED
rubygems · activestorage

Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing

Description

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Affected Products

VendorProductVersions
rubygemsactivestorage< 7.2.3.2, >= 8.0.0.beta1, < 8.0.5.1, >= 8.1.0.beta1, < 8.1.3.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
rubygemsactivestorageGHSA85%

References

  • https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm(x_refsource_CONFIRM)
  • https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e(x_refsource_MISC)
  • https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5(x_refsource_MISC)
  • https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v7.2.3.2(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v8.0.5.1(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v8.1.3.1(x_refsource_MISC)
  • https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.yml(x_refsource_MISC)
  • https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html(x_refsource_MISC)

Related News (14 articles)

Tier E
Hacker News3d ago
Zero-Day to Zero Doubt: AI-Powered CVE Forensics in an Afternoon
→ No new info (linked only)
Tier D
CSO Online4d ago
Ruby on Rails critical bug puts every image upload under scrutiny
→ No new info (linked only)
Tier C
Rapid7 Blog5d ago
Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
→ No new info (linked only)
Tier D
The Hacker News5d ago
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
→ No new info (linked only)
Tier D
Help Net Security5d ago
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
→ No new info (linked only)
Tier B
CERT-FR6d ago
Bulletin d'actualité CERTFR-2026-ACT-033 (03 août 2026)
→ No new info (linked only)
Tier D
BleepingComputer7d ago
Rails patches critical Active Storage flaw with RCE potential
→ No new info (linked only)
Tier D
SecurityWeek7d ago
Ruby on Rails Patches Critical Vulnerability
→ No new info (linked only)
Tier D
Heise Security7d ago
Schlüsselklau bei Ruby on Rails – Kritische Lücke mit präparierten Bildern
→ No new info (linked only)
Tier C
oss-security8d ago
Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
→ No new info (linked only)
Tier B
CCCS Canada8d ago
Rails security advisory (AV26-767)
→ No new info (linked only)
Tier C
VulDB9d ago
CVE-2026-66066 | Rails prior 7.2.3.2/8.0.5.1/8.1.3.1 Active Storage unrestricted upload
→ No new info (linked only)
Tier E
Lobsters Security9d ago
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)
→ No new info (linked only)
Tier E
Reddit r/netsec9d ago
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
activestorage@7.2.3.2activestorage@8.0.5.1activestorage@8.1.3.1
CWECWE-1188
PublishedJul 30, 2026
Tags
GHSA-xr9x-r78c-5hrmrubygems
Trending Score56
Source articles14
Independent14
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Trending: 34
HIGHCVE-2026-45378
Decidim: Verification documents can be downloaded through reusable links
Trending: 33
HIGHCVE-2026-45414
Decidim: JWT-backed authentication can be replayed across organizations
Trending: 25
MEDIUMCVE-2026-45415
Decidim: CSV census record endpoints improper authorization
Trending: 22
MEDIUMCVE-2026-45572
Decidim: HTML content blocks allow stored script execution
Trending: 16

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Patch Available
Aug 5, 2026