Insecure Default Initialization of Resource in activestorage - CVE-2026-66066
Published: August 3, 2026 / Updated: September 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and potentially execute arbitrary code.
The vulnerability exists due to initialization of a resource with an insecure default in Active Storage variant processing when processing a crafted uploaded file to generate an image variant. A remote attacker can upload a crafted file and cause a variant to be generated from it to disclose sensitive information and potentially execute arbitrary code.
Only applications using libvips for Active Storage image processing and allowing image uploads from untrusted users are vulnerable.
Affected software
How to mitigate CVE-2026-66066
Links to Public Exploits and PoC-codes
- Exploit #13053 - KindaRails2Shell (September 4, 2026)
- Exploit #12973 - Ruby on Rails Active Storage Vips Arbitrary File Read and Remote Code Execution (August 25, 2026)
- Exploit #12875 - CVE-2026-66066 (CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged variation. CVSS 9.5 | Rails < 8.1.3.1) (August 6, 2026)