< Back to situations

This situation has concluded

It was preserved as a record on September 2; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 11 sources · 5 days · First seen · Last updated

Ruby on Rails Active Storage vulnerability

Overview

In late July 2026, the Ruby on Rails core team issued urgent security updates to address a critical Active Storage flaw (CVE‑2026‑66066) that could allow unauthenticated attackers to read arbitrary files and potentially achieve remote code execution. The patches targeted Rails 7.0.0–7.2.3.1, 8.0.0–8.0.5, and 8.1.0–8.1.3, upgrading them to versions that block untrusted libvips image loaders. The advisory noted a high CVSS score (9.5) and recommended updating bundles, ensuring libvips 8.13+ is installed, and rotating any possibly exposed secrets. No active exploitation was reported at that time.

A few days later, Japan’s Computer Emergency Response Team (JPCERT/CC) released its own advisory, confirming that exploit code for the same vulnerability had been published publicly. The JPCERT warning emphasized that attacks were likely to increase and urged developers to apply the newly released patches immediately, treat any exposed credentials as compromised, and rotate them. The advisory reinforced the importance of timely patching and robust file‑upload validation for Rails‑based services.

Entities

Active Storage · Ruby on Rails · libvips · André Baptista · GMO Flatt Security

Timeline

  1. about 2 months ago

    [TECHNOLOGY] 5 sources
    Ruby on Rails Active Storage Remote Code Execution Vulnerability

    JPCERT/CC reports a remote code execution flaw (CVE‑2026‑66066) in Ruby on Rails Active Storage affecting versions before 7.2.3.2, 8.0.5.1 and 8.1.3.1; exploit code is public and updates are urged.

  2. about 2 months ago

    [TECHNOLOGY] 6 sources
    Ruby on Rails Issues Critical Active Storage Patch for CVE‑2026‑66066

    Ruby on Rails patched a critical Active Storage bug (CVE‑2026‑66066) that let unauthenticated file reads via libvips. Updates for versions 7.2.3.2, 8.0.5.1, 8.1.3.1 were released on July 29 2026; operators must

Sources

bendyworks.com · countryrebel.com · dev.to · dreamnews.jp · floranews.nl · linuxcompatible.org · rubyland.news · s.netsecurity.ne.jp · scan.netsecurity.ne.jp · socprime.com · youthsoccercup.com