INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Ruby on Rails Patches Critical Active Storage Vulnerability
| 2026-08-01 14:20 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The Ruby on Rails Active Storage vulnerability has been patched, fixing a critical flaw that could have allowed unauthenticated attackers to read arbitrary files from vulnerable servers. The fix involves upgrading the framework to version 8.13 or later and rotating exposed secrets such as secret_key_base. This mitigation is crucial for affected systems using libvips versions older than 8.13, but patching alone may not be enough if attackers have already accessed application secrets.
Technical Mitigations AI-generated
I can provide the following technical mitigations in bullet points:
* Upgrade Active Storage to version 8.13 or later, and update libvips to a compatible version (e.g., 8.14) to prevent exploitation of CVE-2026-66066.
* Rotate exposed secrets such as secret_key_base, encryption keys, cloud storage credentials, database passwords, and third-party service tokens for all applications that allow untrusted image uploads and use Active Storage with libvips.
* Consider rotating application secrets potentially compromised due to the vulnerability, including secret_key_base, environment variables containing application secrets, encrypted cookies, signed URLs, and user authentication data.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
8.0.•••.•••
7.2.•••.•••
6.1.•••.•••
8.1.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-66066CVE-2026-66066
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
Incident Timeline
July 29, 2026
Threat actors used a critical patch for Rails Active Storage to exploit a Remote Code Execution (RCE) vulnerability.
Click on any entity below to view its context and source!
organisation
PoC
Neither research team had published a proof-of-concept (PoC) as of 17:30 UTC on July 29, 2026.
organisation
UTC
Neither research team had published a proof-of-concept (PoC) as of 17:30 UTC on July 29, 2026.
July 29
Threat actors exploited a critical Active Storage flaw in Rails patches.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-66066
A review by The Hacker News at 17:30 UTC on July 29 found that
CVE-2026-66066
was not listed in version 2026.07.27 of CISA's
Known Exploited Vulnerabilities catalog
.
infrastructure
2026.07.27
A review by The Hacker News at 17:30 UTC on July 29 found that
CVE-2026-66066
was not listed in version 2026.07.27 of CISA's
Known Exploited Vulnerabilities catalog
.
attribution
Known Exploited
A review by The Hacker News at 17:30 UTC on July 29 found that
CVE-2026-66066
was not listed in version 2026.07.27 of CISA's
Known Exploited Vulnerabilities catalog
.
tactic
T1588.006 - Vulnerabilities
A review by The Hacker News at 17:30 UTC on July 29 found that
CVE-2026-66066
was not listed in version 2026.07.27 of CISA's
Known Exploited Vulnerabilities catalog
.
July 30, 2026
Threat actors exploited a critical vulnerability in Rails patches for Active Storage, allowing them to execute arbitrary code with Remote Code Execution (RCE) potential.
2026/08/01
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution.
Click on any entity below to view its context and source!
organisation
ImageMagick
Active Storage may also
generate image thumbnails
from uploaded media using image processing libraries such as libvips or
ImageMagick
.
organisation
Rails
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).
“In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment.”
reads the advisory
.
Tracked as
CVE-2026-66066
(CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as
secret_key_base
, the Rails master key, database passwords, cloud storage credentials, and API tokens.
organisation
API
Tracked as
CVE-2026-66066
(CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as
secret_key_base
, the Rails master key, database passwords, cloud storage credentials, and API tokens.
organisation
CVE-2026
CVE-2026-66066 impacts Active Storage before 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1.
organisation
GMO Flatt Security Inc.
The vulnerability was discovered and responsibly reported to the Rails team by researchers from Ethiack and GMO Flatt Security Inc.
Security firm Akamai has also published a warning about CVE-2026-66066, naming the attack chain “KindaRails2Shell,” and warning about its RCE potential.
organisation
Akamai
The vulnerability was discovered and responsibly reported to the Rails team by researchers from Ethiack and GMO Flatt Security Inc.
Security firm Akamai has also published a warning about CVE-2026-66066, naming the attack chain “KindaRails2Shell,” and warning about its RCE potential.
organisation
KindaRails2Shell
The vulnerability was discovered and responsibly reported to the Rails team by researchers from Ethiack and GMO Flatt Security Inc.
Security firm Akamai has also published a warning about CVE-2026-66066, naming the attack chain “KindaRails2Shell,” and warning about its RCE potential.
organisation
Ruby on Rails
Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary files from vulnerable servers.
organisation
Operators
Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the application process.
organisation
RCE
Rails patches critical Active Storage flaw with RCE potential.
The researchers have not disclosed the malicious format, file-read construction, or RCE chain.
organisation
Active Storage
The Rails team recommends upgrading to
libvips 8.13
or later and rotating the ‘secret_key_base’ (the Rails master key), database credentials, Active Storage service credentials, and any other secrets accessible to the application process.
Fixed versions of Active Storage have been released, while technical exploit details will be disclosed later to reduce abuse against unpatched systems.
Rails tells operators to rotate
secret_key_base
, the master key and decrypted credentials, database credentials, Active Storage service keys, and third-party tokens.
infrastructure
8.13 libvips
The Rails team recommends upgrading to
libvips 8.13
or later and rotating the ‘secret_key_base’ (the Rails master key), database credentials, Active Storage service credentials, and any other secrets accessible to the application process.
For systems running libvips 8.13 or later, administrators can temporarily disable the vulnerable functionality by setting the VIPS_BLOCK_UNTRUSTED environment variable or calling Vips.block_untrusted(true) when using ruby-vips 2.2.1 or newer.
The fix is to upgrade Active Storage, update libvips to version 8.13 or later, and rotate exposed secrets such as
secret_key_base
.
With libvips 8.13 or later, risky “unfuzzed” operations can be disabled through environment settings or ruby-vips configuration.
Applications that cannot immediately update Rails can set
VIPS_BLOCK_UNTRUSTED
when running libvips 8.13 or later, or call
Vips.block_untrusted(true)
with ruby-vips 2.2.1 or later.
Patched installations require libvips 8.13 or later and, when ruby-vips is installed, ruby-vips 2.2.1 or later.
infrastructure
8.13
The fix is to upgrade Active Storage, update libvips to version 8.13 or later, and rotate exposed secrets such as
secret_key_base
.
Applications that cannot immediately update Rails can set
VIPS_BLOCK_UNTRUSTED
when running libvips 8.13 or later, or call
Vips.block_untrusted(true)
with ruby-vips 2.2.1 or later.
For affected systems using libvips versions older than 8.13, the only mitigation is removing the dependency.
infrastructure
2.2.1
Applications that cannot immediately update Rails can set
VIPS_BLOCK_UNTRUSTED
when running libvips 8.13 or later, or call
Vips.block_untrusted(true)
with ruby-vips 2.2.1 or later.
organisation
PoC
However, because public proof-of-concept (PoC) exploits became available very quickly, the maintainers decided to
publish the full details
as well as
forensic investigation tooling
.
organisation
WAF
Ethiack
noted
that a WAF might buy admins some time, but attackers using AI tooling should be able to reconstruct the attack chain based on the patch diffs.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
the Ruby on Rails Active Storage
According to the advisory, patching the Ruby on Rails Active Storage vulnerability is not enough if attackers have already accessed application secrets.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Ruby on Rails)
infrastructure
9.5
The 9.5 score describes severity under CVSS, not how many deployments are exposed: a vulnerable deployment must also use Vips, accept untrusted image uploads, and include an exploitable operation in its libvips build.
organisation
CVSS
The 9.5 score describes severity under CVSS, not how many deployments are exposed: a vulnerable deployment must also use Vips, accept untrusted image uploads, and include an exploitable operation in its libvips build.
infrastructure
6.0.0
Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configured to use Vips, which was not the default processor in Rails 6.
infrastructure
6.1.7
Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configured to use Vips, which was not the default processor in Rails 6.
infrastructure
7.2
It said the public advisory covers Rails releases under security support, meaning Rails 7.2, 8.0, and 8.1, while Rails 6.x is also affected when Vips is enabled, which was not the default at the time.
infrastructure
8.0
It said the public advisory covers Rails releases under security support, meaning Rails 7.2, 8.0, and 8.1, while Rails 6.x is also affected when Vips is enabled, which was not the default at the time.
infrastructure
8.1
It said the public advisory covers Rails releases under security support, meaning Rails 7.2, 8.0, and 8.1, while Rails 6.x is also affected when Vips is enabled, which was not the default at the time.
organisation
Image Uploads
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads.
organisation
The Rails Security Team
The Rails Security Team told The Hacker News that the researchers' affected range is accurate.
organisation
The Hacker News
The Rails Security Team told The Hacker News that the researchers' affected range is accurate.
organisation
MiniMagick
Applications using MiniMagick are not exposed through this specific attack path.
organisation
MATLAB
The code uses a crafted MATLAB/HDF5 upload to read the Rails process environment, recover
SECRET_KEY_BASE
, sign an embedded Marshal payload, and trigger an out-of-band
curl
callback.
August 28
Threat actors used a critical patch for Rails to target an Active Storage vulnerability.
August 28, 2026
Threat actors exploited a critical vulnerability in Rails patches for Active Storage, allowing them to execute arbitrary code with Remote Code Execution (RCE) potential.
no later than August 28, 2026
Threat actors exploited a previously unknown critical vulnerability in Rails, allowing them to execute arbitrary code via Remote Code Execution (RCE).
Tactical Metrics
Metrics
infrastructure
8
Libvips
Click for context!
The Rails team recommends upgrading to
libvips 8.13
or later and rotating the ‘secret_key_base’ (the Rails master key), database credentials, Active Storage service credentials, and any other secrets accessible to the application process.
For systems running libvips 8.13 or later, administrators can temporarily disable the vulnerable functionality by setting the VIPS_BLOCK_UNTRUSTED environment variable or calling Vips.block_untrusted(true) when using ruby-vips 2.2.1 or newer.
The fix is to upgrade Active Storage, update libvips to version 8.13 or later, and rotate exposed secrets such as
secret_key_base
.
With libvips 8.13 or later, risky “unfuzzed” operations can be disabled through environment settings or ruby-vips configuration.
Applications that cannot immediately update Rails can set
VIPS_BLOCK_UNTRUSTED
when running libvips 8.13 or later, or call
Vips.block_untrusted(true)
with ruby-vips 2.2.1 or later.
Patched installations require libvips 8.13 or later and, when ruby-vips is installed, ruby-vips 2.2.1 or later.
Metrics
infrastructure
8.13
Software Version
The fix is to upgrade Active Storage, update libvips to version 8.13 or later, and rotate exposed secrets such as
secret_key_base
.
For affected systems using libvips versions older than 8.13, the only mitigation is removing the dependency.
Applications that cannot immediately update Rails can set
VIPS_BLOCK_UNTRUSTED
when running libvips 8.13 or later, or call
Vips.block_untrusted(true)
with ruby-vips 2.2.1 or later.
Metrics
infrastructure
6.0.0
Software Version
Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configured to use Vips, which was not the default processor in Rails 6.
Metrics
infrastructure
6.1.7
Software Version
Rails 6.0.0 through 6.1.7.10 releases are affected only when Active Storage is configured to use Vips, which was not the default processor in Rails 6.
Metrics
infrastructure
7.2
Software Version
It said the public advisory covers Rails releases under security support, meaning Rails 7.2, 8.0, and 8.1, while Rails 6.x is also affected when Vips is enabled, which was not the default at the time.
Metrics
infrastructure
8.0
Software Version
It said the public advisory covers Rails releases under security support, meaning Rails 7.2, 8.0, and 8.1, while Rails 6.x is also affected when Vips is enabled, which was not the default at the time.
Metrics
infrastructure
8.1
Software Version
It said the public advisory covers Rails releases under security support, meaning Rails 7.2, 8.0, and 8.1, while Rails 6.x is also affected when Vips is enabled, which was not the default at the time.
Metrics
infrastructure
2.2.1
Software Version
Applications that cannot immediately update Rails can set
VIPS_BLOCK_UNTRUSTED
when running libvips 8.13 or later, or call
Vips.block_untrusted(true)
with ruby-vips 2.2.1 or later.
Metrics
infrastructure
2026.07.27
Software Version
A review by The Hacker News at 17:30 UTC on July 29 found that
CVE-2026-66066
was not listed in version 2026.07.27 of CISA's
Known Exploited Vulnerabilities catalog
.
Metrics
infrastructure
9.5
Software Version
The 9.5 score describes severity under CVSS, not how many deployments are exposed: a vulnerable deployment must also use Vips, accept untrusted image uploads, and include an exploitable operation in its libvips build.
Intelligence Sources
The Hacker News
2026-07-29
Security Affairs
2026-08-03
BleepingComputer
2026-08-01
Rails patches critical Active Storage flaw with RCE potential
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-03T10:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
ImageMagick
entity
9x
infrastructure
Software Version
8.13
version
7x
timeline
Temporal Reference
August 28
date
5x
general metric
Rails
6
rails
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
general metric
%
54
%
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Contextual Telemetry
Context Block
8 METRICS
industry
Targeted Sector
Media
sector
vulnerability
Exploited CVE
CVE-2026-66066
cve
infrastructure
Libvips
8
libvips
target region
Target Country
United States
country
vulnerability
CVSS Score
10
score
general metric
Score
10
score
attribution
Attributing Entity
Known Exploited
authority
general metric
Load_Defaults
7
load_defaults
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.