THREATOPS
THREAT OPSThreat News › Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing

Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing

medoss_secPublished 2026-07-29

<p>Posted by Alan Coopersmith on Jul 29</p><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm" rel="nofollow">https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm</a><br /> advises:<br />

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/324

Same event, other sources