THREAT OPS › Threat News › KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style="font-size: undefined;">On July 29, 2026, the Ruby on Rails project </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span style="font-size: undefined;">published a security advisory</span></a><span style="font-size: undefined;"> for </span><a href="https://www.cve.org/CVERecord?i
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 349e7a5d5b4b715af1e416db824f3c078a7d59e5sha1
- CVE-2026-66066cve
- https://www.cve.org/CVERecord?id=CVE-2026-66066url
- https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:Hurl
- https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066url
- https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432url
- 7.2.3.2ipv4
- 8.0.5.1ipv4
- 8.1.3.1ipv4
- 7.2.3.1ipv4
- 6.1.7.10ipv4
Original source: https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails
Same event, other sources
- Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processingoss_sec · 2026-07-29
- CVE-2026-66066: Defending Against the “KindaRails2Shell” Pre-Auth RCEakamai_blog · 2026-07-30
- [NVD] CVE-2026-66066 — Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applnvd · 2026-07-30
- Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processingoss_sec · 2026-08-01
- Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)rapid7 · 2026-08-03