<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Ruby on Rails Patches Critical RCE Vulnerability

Patch critical Ruby on Rails vulnerability (CVE-2026-66066) affecting Active Storage. Update libvips to avoid RCE threats now.
Content Team

Ruby on Rails has patched a critical vulnerability (CVE-2026-66066, CVSS 9.5) that could let unauthenticated attackers read arbitrary files and achieve remote code execution. The flaw affects applications using the libvips library for Active Storage image processing that accept uploads from untrusted users — a very common setup. Attackers could upload a crafted file to expose secrets like secret_key_base, then escalate to full RCE or lateral movement. Fixes are available in Active Storage versions 7.2.3.2, 8.0.5.1, and 8.1.3.1. Updating libvips to at least version 8.13 is also required. As of July 30, no active exploitation has been detected, but any previously exposed secrets should be rotated immediately.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo