Security · 1h ago
Critical Rails Flaw Lets Attackers Read Server Files via Image Uploads
Ruby on Rails patched a critical Active Storage vulnerability (CVE-2026-66066, CVSS 9.5) that allows unauthenticated attackers to read arbitrary files from application servers through crafted image uploads. The flaw could expose environment secrets including secret_key_base, database passwords, and cloud storage credentials. Rails users should update immediately to prevent data breaches.
Meridian48 take
This is a high-severity, easily exploitable bug in a widely used framework—teams running Rails should treat this as a priority patch, not just another routine update.
Read the full reporting
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads →
The Hacker News
ruby-on-railsactive-storage