THREAT OPS › Threat News › Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processing
<p>Posted by Alan Coopersmith on Jul 31</p>[...]<br /> <br /> That further disclosure has happened now, announced at:<br /> <a href="https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441" rel="nofollow">https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441</a><br />
Indicators of compromise
- CVE-2026-66066cve
- https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441url
Original source: https://seclists.org/oss-sec/2026/q3/377
Same event, other sources
- Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processingoss_sec · 2026-07-29
- CVE-2026-66066: Defending Against the “KindaRails2Shell” Pre-Auth RCEakamai_blog · 2026-07-30
- KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Railsrapid7 · 2026-07-30
- [NVD] CVE-2026-66066 — Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applnvd · 2026-07-30
- Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)rapid7 · 2026-08-03