Insecure Default Initialization of Resource in activestorage - CVE-2026-66066

 

Insecure Default Initialization of Resource in activestorage - CVE-2026-66066

Published: August 3, 2026


Vulnerability identifier: #VU140820
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66066
CWE-ID: CWE-1188
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and potentially execute arbitrary code.

The vulnerability exists due to initialization of a resource with an insecure default in Active Storage variant processing when processing a crafted uploaded file to generate an image variant. A remote attacker can upload a crafted file and cause a variant to be generated from it to disclose sensitive information and potentially execute arbitrary code.

Only applications using libvips for Active Storage image processing and allowing image uploads from untrusted users are vulnerable.


Affected software

activestorage

How to mitigate CVE-2026-66066

Install security update from vendor's website.

activestorage - addressed in versions 7.2.3.2, 8.0.5.1, 8.1.3.1

External References

Related Security Bulletins