Ruby on Rails Patches Critical RCE Vulnerability
Patch critical Ruby on Rails vulnerability (CVE-2026-66066) affecting Active Storage. Update libvips to avoid RCE threats now.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
Ruby on Rails has patched a critical vulnerability (CVE-2026-66066, CVSS 9.5) that could let unauthenticated attackers read arbitrary files and achieve remote code execution. The flaw affects applications using the libvips library for Active Storage image processing that accept uploads from untrusted users — a very common setup. Attackers could upload a crafted file to expose secrets like secret_key_base, then escalate to full RCE or lateral movement. Fixes are available in Active Storage versions 7.2.3.2, 8.0.5.1, and 8.1.3.1. Updating libvips to at least version 8.13 is also required. As of July 30, no active exploitation has been detected, but any previously exposed secrets should be rotated immediately.
Source: SecurityWeek
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo