A critical vulnerability in Ruby on Rails’ Active Storage component could allow unauthenticated attackers to read arbitrary files on vulnerable application servers, potentially escalating to remote code execution. This vulnerability is tracked as CVE-2026-66066 and affects Active Storage variant processing in Rails applications configured to use libvips for image manipulation. Rails maintainers disclosed the issue […]
Read the original article: