Per Bleeping Computer, a critical vulnerability identified as CVE-2026-66066 has been discovered in the Active Storage component of the Ruby on Rails web application framework. This flaw allows unauthenticated attackers to potentially read arbitrary files from a vulnerable server and escalate to remote code execution (RCE).The vulnerability specifically affects Active Storage versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1, particularly when the libvips image processing library is in use. Attackers can exploit this by uploading a specially crafted image to a server that allows untrusted image uploads. Successful exploitation could grant access to sensitive application files, including the process environment which often contains critical credentials like the secret_key_base, database passwords, and cloud storage keys.Security firm Akamai has dubbed the attack chain "KindaRails2Shell," emphasizing that compromising the secret_key_base allows for session cookie forgery, global ID signing, and manipulation of serialized data, leading to full RCE. While ImageMagick users are unaffected, libvips is the default processor in official Rails Docker images and common Linux distributions. The Rails team recommends upgrading libvips to version 8.13 or later and rotating all sensitive credentials. Forensic investigation tools and detailed technical information have been released due to the rapid emergence of proof-of-concept exploits.Source: Bleeping Computer
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
