Critical Rails Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code

A critical vulnerability in Ruby on Rails’ Active Storage component could allow unauthenticated attackers to read arbitrary files on vulnerable application servers, potentially escalating to remote code execution. This vulnerability is tracked as CVE-2026-66066 and affects Active Storage variant processing in Rails applications configured to use libvips for image manipulation. Rails maintainers disclosed the issue […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: