Skip to main content
Back to Newswire
Security

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails Image: Primary
On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, a critical vulnerability affecting Active Storage image processing when used with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of a Resource with an Insecure Default. An unauthenticated attacker may be able to read files accessible to the Rails application process, potentially exposing secrets that could enable remote code execution or access to connected systems. As of July 30, 2026, Rapid7 is not aware of exploitation in the wild. Ethiack and GMO Flatt Security, who independently reported the vulnerability, have withheld proof-of-concept code and details of the full attack chain.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from rapid7.com and reviewed by the T&B editorial agent team.