Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 9 sources · 5 days · First seen · Last updated
Categories: TECHNOLOGY
Ruby on Rails Active Storage vulnerability
Entities: Active Storage · Ruby on Rails · libvips · André Baptista · GMO Flatt Security
Overview
In late July 2026, the Ruby on Rails core team issued urgent security updates to address a critical Active Storage flaw (CVE‑2026‑66066) that could allow unauthenticated attackers to read arbitrary files and potentially achieve remote code execution. The patches targeted Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, and 8.1.0–8.1.3, upgrading them to versions that block untrusted libvips image loaders. The advisory noted a high CVSS score (9.5) and recommended updating bundles, ensuring libvips 8.13+ is installed, and rotating any possibly exposed secrets. No active exploitation was reported at that time.
A few days later, Japan’s Computer Emergency Response Team (JPCERT/CC) released its own advisory, confirming that exploit code for the same vulnerability had been published publicly. The JPCERT warning emphasized that attacks were likely to increase and urged developers to apply the newly released patches immediately, treat any exposed credentials as compromised, and rotate them. The advisory reinforced the importance of timely patching and robust file‑upload validation for Rails‑based services.
Timeline
-
about 7 hours ago
[TECHNOLOGY] 3 sourcesRuby on Rails Active Storage Remote Code Execution VulnerabilityJPCERT/CC reports a remote code execution flaw (CVE‑2026‑66066) in Ruby on Rails Active Storage affecting versions before 7.2.3.2, 8.0.5.1 and 8.1.3.1; exploit code is public and updates are urged.
-
5 days ago
[TECHNOLOGY] 6 sourcesRuby on Rails Issues Critical Active Storage Patch for CVE‑2026‑66066Ruby on Rails patched a critical Active Storage bug (CVE‑2026‑66066) that let unauthenticated file reads via libvips. Updates for versions 7.2.3.2, 8.0.5.1, 8.1.3.1 were released on July 29 2026; operators must
Sources
countryrebel.com · dev.to · dreamnews.jp · floranews.nl · linuxcompatible.org · rubyland.news · s.netsecurity.ne.jp · socprime.com · youthsoccercup.com