Vulnerability Management

Critical vulnerability in Rails Active Storage could lead to RCE

Adobe Stock

Per Bleeping Computer, a critical vulnerability identified as CVE-2026-66066 has been discovered in the Active Storage component of the Ruby on Rails web application framework. This flaw allows unauthenticated attackers to potentially read arbitrary files from a vulnerable server and escalate to remote code execution (RCE).

The vulnerability specifically affects Active Storage versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1, particularly when the libvips image processing library is in use. Attackers can exploit this by uploading a specially crafted image to a server that allows untrusted image uploads. Successful exploitation could grant access to sensitive application files, including the process environment which often contains critical credentials like the secret_key_base, database passwords, and cloud storage keys.

Security firm Akamai has dubbed the attack chain "KindaRails2Shell," emphasizing that compromising the secret_key_base allows for session cookie forgery, global ID signing, and manipulation of serialized data, leading to full RCE. While ImageMagick users are unaffected, libvips is the default processor in official Rails Docker images and common Linux distributions. The Rails team recommends upgrading libvips to version 8.13 or later and rotating all sensitive credentials. Forensic investigation tools and detailed technical information have been released due to the rapid emergence of proof-of-concept exploits.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds