Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-66066] KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Rails

ethiack.com | research | CVE-2026-66066 | #rce | #ruby-on-rails | #libvips | #file-read | #cve-2026-66066

Summary

A technical deep-dive into CVE-2026-66066, where a malformed MATLAB file slips past libvips handling in Rails ActiveStorage to achieve arbitrary file read and unauthenticated RCE on default setups.
Collected

original ↗

Related coverage

back