Critical RCE Vulnerability in Rails Active Storage Threatens Default Configs

rez0__ · x · 2026-07-29

Security researchers have disclosed a critical Remote Code Execution (RCE) vulnerability in Ruby on Rails, dubbed KindaRails2Shell (CVE-2026-66066).

The flaw resides in Rails' default Active Storage file processing component combined with the vips image processor. Under default configurations, applications are exposed if they accept image uploads from untrusted users. This affects default Rails 7.x/8.x and customized 6.x versions.

Developers are urged to patch immediately. The researchers note that simply upgrading Rails is insufficient if the underlying libvips library is older than version 8.13. While a WAF might slow down attackers, it is not a definitive fix.

Original post →

More from Safety

Safety channel →