Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-66066PATCHED
rubygems · activestorage

Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing

Description

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Affected Products

VendorProductVersions
rubygemsactivestorage< 7.2.3.2, >= 8.0.0.beta1, < 8.0.5.1, >= 8.1.0.beta1, < 8.1.3.1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ibmlicense metric toolcert_advisory90%
rubygemsactivestorageGHSA85%

References

  • https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm(x_refsource_CONFIRM)
  • https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e(x_refsource_MISC)
  • https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5(x_refsource_MISC)
  • https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v7.2.3.2(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v8.0.5.1(x_refsource_MISC)
  • https://github.com/rails/rails/releases/tag/v8.1.3.1(x_refsource_MISC)
  • https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.yml(x_refsource_MISC)
  • https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html(x_refsource_MISC)

Related News (16 articles)

Tier B
BSI Advisories2d ago
[NEU] [hoch] IBM License Metric Tool: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Help Net Security14d ago
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
→ No new info (linked only)
Tier E
Hacker News18d ago
Zero-Day to Zero Doubt: AI-Powered CVE Forensics in an Afternoon
→ No new info (linked only)
Tier D
CSO Online19d ago
Ruby on Rails critical bug puts every image upload under scrutiny
→ No new info (linked only)
Tier C
Rapid7 Blog20d ago
Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
→ No new info (linked only)
Tier D
The Hacker News20d ago
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
→ No new info (linked only)
Tier D
Help Net Security20d ago
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
→ No new info (linked only)
Tier B
CERT-FR21d ago
Bulletin d'actualité CERTFR-2026-ACT-033 (03 août 2026)
→ No new info (linked only)
Tier D
BleepingComputer22d ago
Rails patches critical Active Storage flaw with RCE potential
→ No new info (linked only)
Tier D
SecurityWeek22d ago
Ruby on Rails Patches Critical Vulnerability
→ No new info (linked only)
Tier D
Heise Security22d ago
Schlüsselklau bei Ruby on Rails – Kritische Lücke mit präparierten Bildern
→ No new info (linked only)
Tier C
oss-security23d ago
Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
→ No new info (linked only)
Tier B
CCCS Canada23d ago
Rails security advisory (AV26-767)
→ No new info (linked only)
Tier C
VulDB24d ago
CVE-2026-66066 | Rails prior 7.2.3.2/8.0.5.1/8.1.3.1 Active Storage unrestricted upload
→ No new info (linked only)
Tier E
Lobsters Security24d ago
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)
→ No new info (linked only)
Tier E
Reddit r/netsec24d ago
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
activestorage@7.2.3.2activestorage@8.0.5.1activestorage@8.1.3.1
CWECWE-1188
PublishedJul 30, 2026
Tags
GHSA-xr9x-r78c-5hrmrubygems
Trending Score61
Source articles16
Independent15
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-61666
websocket-driver: Denial of service via malformed Host header
Trending: 8
HIGHCVE-2026-45378
Decidim: Verification documents can be downloaded through reusable links
Trending: 7
NONECVE-2026-71847
Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams
Trending: 6
HIGHCVE-2026-45414
Decidim: JWT-backed authentication can be replayed across organizations
Trending: 5
MEDIUMCVE-2026-45415
Decidim: CSV census record endpoints improper authorization
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 30, 2026
Discovered by ZDM
Jul 30, 2026
Patch Available
Aug 5, 2026