THREAT OPS › Threat News › [GHSA] GHSA-xr9x-r78c-5hrm (critical) — Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
[GHSA] GHSA-xr9x-r78c-5hrm (critical) — Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
GHSA-xr9x-r78c-5hrm Severity: critical CVE: CVE-2026-66066
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typical
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-66066cve
- https://discuss.rubyonrails.org/c/security-announcements/9url
- https://ethiack.comurl
- https://ryotak.neturl
- https://flatt.tech/en/url
- https://www.libvips.org/2022/05/28/Whaturl
- https://doi.org/10.1109/2.889093url
- https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cveurl
- https://blog.flatt.tech/entry/kindarails2shell_railsurl
- 7.2.3.2ipv4
- 8.0.5.1ipv4
- 8.1.3.1ipv4
Original source: https://github.com/advisories/GHSA-xr9x-r78c-5hrm