THREAT OPS › Threat News › Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style="font-size: undefined;">On July 29, 2026, the Ruby on Rails project published a </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span style="font-size: undefined;">security advisory</span></a><span style="font-size: undefined;"> for </span><a href="https://www.rapid7.com/db/vulne
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-66066cve
- 7.2.3.2ipv4
- 8.0.5.1ipv4
- 8.1.3.1ipv4
- 6.0.6.1ipv4
- 6.1.7.10ipv4
- 7.2.3.1ipv4
Original source: https://www.rapid7.com/blog/post/ra-kindarails2shell-technical-analysis-cve-2026-66066
Same event, other sources
- Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processingoss_sec · 2026-07-29
- CVE-2026-66066: Defending Against the “KindaRails2Shell” Pre-Auth RCEakamai_blog · 2026-07-30
- KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Railsrapid7 · 2026-07-30
- [NVD] CVE-2026-66066 — Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applnvd · 2026-07-30
- Re: Rails CVE-2026-66066: Possible arbitrary file read and remote code execution in Active Storage variant processingoss_sec · 2026-08-01