THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xr9x-r78c-5hrm (critical) — Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

[GHSA] GHSA-xr9x-r78c-5hrm (critical) — Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

highgithub_advisoriesPublished 2026-07-30

GHSA-xr9x-r78c-5hrm Severity: critical CVE: CVE-2026-66066

Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing

### Impact In its default configuration, a Rails application that displays image variants may allow an unauthenticated attacker to read arbitrary files from the server, including the process environment. That environment typical

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xr9x-r78c-5hrm