Security · 1h ago
Critical Rails Active Storage Bug Allows Remote Code Execution
CVE-2026-66066 affects Active Storage when using libvips for image variant processing. Attackers can read arbitrary files and potentially execute code remotely. Patches are available for Rails 7.2.3.2, 8.0.5.1, and 8.1.3.1.
Meridian48 take
The advisory's blunt recommendation to rotate secrets underscores that patching alone may not be enough if exploitation already occurred.
railsactive-storage