Public PoC Released for Critical Rails Active Storage RCE Vulnerability

A critical vulnerability in Ruby on Rails has raised new concerns about cloud data breaches, particularly for companies that host customer platforms in Amazon Web Services (AWS). Known as CVE-2026-66066 or KindaRails2Shell, this flaw affects Active Storage deployments that utilize the libvips image-processing library and accept uploads from untrusted users. While there is no specific […]

This article has been indexed from Cyber Security News

Read the original article: