KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)
ethiack.com | vulnerability | Critical | CVE-2026-66066 | #rce | #ruby-on-rails | #active-storage | #libvips | #arbitrary-file-read | #featured | #cve-2026-66066 | #ethiack
Summary
Ethiack research team discovered KindaRails2Shell (CVE-2026-66066): a critical RCE in Ruby on Rails via Active Storage. 500,000+ sites affected. Find out if you are and how to mitigate.
Why it matters
A default Rails image-processing path can expose process secrets and lead to remote code execution. Defenders must upgrade both Active Storage and libvips, then rotate any secrets that may already have been readable.
- Vendor
- Ruby on Rails
- Product
- Active Storage
- Affected versions
- Active Storage < 7.2.3.2; >= 8.0 and < 8.0.5.1; >= 8.1 and < 8.1.3.1; libvips must be >= 8.13
- CVSS
- 9.5
- Published
- Collected
Skip to content