BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Rails critical Active Storage bug lets attackers read files remotely

Critical Rails Active Storage flaw allows unauthenticated file read via crafted image uploads.

  • Ruby on Rails patched a critical Active Storage vulnerability, CVE-2026-66066 (CVSS 9.5), allowing unauthenticated file read on servers using libvips.
  • Attackers can extract secret_key_base, database passwords, cloud storage credentials, and API tokens, potentially enabling remote code execution or lateral movement.
  • Affected versions include Rails 7.0 through 7.2.3.1, 8.0.0–8.0.5, and 8.1.0–8.1.3; operators must upgrade to patched releases and rotate all exposed secrets.

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS 9.5), the flaw exposes the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, and cloud storage credentials.

- Advertisement -

Affected applications use libvips for Active Storage image processing and accept image uploads from untrusted users. The Rails security advisory explains that libvips supports loaders and savers backed by third-party libraries marked “untrusted.” Active Storage did not block them, allowing a crafted upload to invoke one and disclose files readable by the Rails worker.

Ethiack and GMO Flatt Security list the affected ranges as Rails 7.0.0 through 7.2.3.1, Rails 8.0.0 through 8.0.5, and Rails 8.1.0 through 8.1.3. The official advisory notes that activestorage < 7.2.3.2 is vulnerable, and applications using MiniMagick are not exposed through this specific attack path.

Operators should upgrade to Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1 and rotate every secret readable by the application process. The patch calls Vips.block_untrusted(true) when Active Storage starts, and patched installations require libvips 8.13 or later.

Rails credited André Baptista, Bruno Mendes, and Rafael Castilho of Ethiack, and RyotaK of GMO Flatt Security, with independently reporting the issue. Neither research team had published a proof-of-concept by 17:30 UTC on July 29, 2026, and no in-the-wild exploitation was reported.

- Advertisement -

The flaw was not listed in CISA's Known Exploited Vulnerabilities catalog as of version 2026.07.27. Rails warned that applying the patch does not invalidate credentials that may already have been stolen.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

OpenAI Fires 3 Researchers for Leaking Secrets to Safety Group

OpenAI confirmed it fired three safety researchers for allegedly sharing confidential information with an...

Nvidia’s Hyperscaler Revenue Seen at $237B in 2026: Barclays

Barclays analyst Tom O’Malley’s “napkin math” projects NVIDIA could generate $237 billion in hyperscaler...

MetaMask Proactively Exits 17K Validators After Breach

MetaMask proactively exited over 523,000 staked ETH ($1.4 billion) across 17,000 validators following a...

LatAm stablecoin liquidity hinges on few providers: report

A new report from Varys Capital and Verda Ventures found only 16 companies in...

WordPress SC Malware: 8 Persistence Methods, Blockchain C2

Security researchers have uncovered a WordPress malware codenamed SC that uses the Ethereum blockchain...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading