Browsing Tag

CVE-2026-66066

1 post

Coverage of CVE-2026-66066, the Rails Active Storage and libvips arbitrary file read vulnerability.

Laptop screen showing code at a developer workstation

Rails Active Storage Flaw Turns Image Uploads Into a Secret-Rotation Drill

Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw that can let attackers turn image uploads into arbitrary file reads and possible remote code execution. For affected teams, the job is not only upgrading Rails and libvips, but checking exposure windows and rotating secrets that may have been readable by the Rails process.
Read More