< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 9 sources · 5 days · First seen · Last updated

Categories: TECHNOLOGY

Ruby on Rails Active Storage vulnerability

Entities: Active Storage · Ruby on Rails · libvips · André Baptista · GMO Flatt Security

Overview

In late July 2026, the Ruby on Rails core team issued urgent security updates to address a critical Active Storage flaw (CVE‑2026‑66066) that could allow unauthenticated attackers to read arbitrary files and potentially achieve remote code execution. The patches targeted Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, and 8.1.0–8.1.3, upgrading them to versions that block untrusted libvips image loaders. The advisory noted a high CVSS score (9.5) and recommended updating bundles, ensuring libvips 8.13+ is installed, and rotating any possibly exposed secrets. No active exploitation was reported at that time.

A few days later, Japan’s Computer Emergency Response Team (JPCERT/CC) released its own advisory, confirming that exploit code for the same vulnerability had been published publicly. The JPCERT warning emphasized that attacks were likely to increase and urged developers to apply the newly released patches immediately, treat any exposed credentials as compromised, and rotate them. The advisory reinforced the importance of timely patching and robust file‑upload validation for Rails‑based services.

Timeline

  1. about 7 hours ago

    [TECHNOLOGY] 3 sources
    Ruby on Rails Active Storage Remote Code Execution Vulnerability

    JPCERT/CC reports a remote code execution flaw (CVE‑2026‑66066) in Ruby on Rails Active Storage affecting versions before 7.2.3.2, 8.0.5.1 and 8.1.3.1; exploit code is public and updates are urged.

  2. 5 days ago

    [TECHNOLOGY] 6 sources
    Ruby on Rails Issues Critical Active Storage Patch for CVE‑2026‑66066

    Ruby on Rails patched a critical Active Storage bug (CVE‑2026‑66066) that let unauthenticated file reads via libvips. Updates for versions 7.2.3.2, 8.0.5.1, 8.1.3.1 were released on July 29 2026; operators must

Sources

countryrebel.com · dev.to · dreamnews.jp · floranews.nl · linuxcompatible.org · rubyland.news · s.netsecurity.ne.jp · socprime.com · youthsoccercup.com