vulnerability Ruby on Rails Patches Critical Vulnerability A critical vulnerability in Ruby on Rails, specifically related to image processing using the libvips library, has been patched. Attackers could potentially read arbitrary files and expose secrets, leading to remote code execution and lateral movement. The vulnerability affects applications using specific versions of A… SecurityWeek · Aug 1, 2026 Critical CVE-2026-66066rubyrailslibvips
vulnerability Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads A critical vulnerability (CVE-2026-66066, CVSS 9.5) in Ruby on Rails' Active Storage component, using libvips for image processing, allows unauthenticated attackers to read arbitrary files from application servers. This… The Hacker News · Jul 29, 2026 Critical CVE-2026-66066rubyrailslibvips