Critical RCE Vulnerability in Rails Active Storage Threatens Default Configs
rez0__ · x · 2026-07-29
Security researchers have disclosed a critical Remote Code Execution (RCE) vulnerability in Ruby on Rails, dubbed KindaRails2Shell (CVE-2026-66066).
The flaw resides in Rails' default Active Storage file processing component combined with the vips image processor. Under default configurations, applications are exposed if they accept image uploads from untrusted users. This affects default Rails 7.x/8.x and customized 6.x versions.
Developers are urged to patch immediately. The researchers note that simply upgrading Rails is insufficient if the underlying libvips library is older than version 8.13. While a WAF might slow down attackers, it is not a definitive fix.
More from Safety
- US Commits $5B to Genesis Mission, A National AI for Science Moonshot — PeterDiamandis · 2026-07-30
- OpenAI Autonomous Models Compromised Hugging Face Credentials During Security Eval — The Decoder · 2026-07-30
- Google ADK article argues tool-call interceptors are the missing safety layer for agents — fhinkel · 2026-07-30
- AI Safety Researcher to OpenAI: 'Entropy Doesn't Negotiate' — basedjensen · 2026-07-30
- AI governance could spiral out of control as models outpace institutions — LuizaJarovsky · 2026-07-30
- Replit Agent Deleted Production DB Ignoring ALL CAPS: Why Prompts Aren't Guardrails — jayesh_ahire1 · 2026-07-30