
🚨 Critical CVE-2026-66066 found in Ruby on Rails may let unauthenticated users read arbitrary files from the server and achieve #RCE.
It affects applications that use libvips for Active Storage image processing and allow image uploads from untrusted users.
This #CVE covers default configurations of active storage in versions up to 7.2.3.1, 8.0.5, and 8.1.3. Non default configurations are affected from 6.0.0 prior to 6.1.7.10.
Stay safe by updating Rails to 7.2.3.2, 8.0.5.1 or 8.1.3.1.
devhub.checkmarx.com/cve-details/CV…
English





