CVE Explorer
CVE-2026-66066
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"rails","vendor":"rails","versions":[{"status":"affected","version":"< 7.2.3.2"},{"status":"affected","version":">= 8.0.0.beta1, < 8.0.5.1"},{"status":"affected","version":">= 8.1.0.beta1, < 8.1.3.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":9.5,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1188","description":"CWE-1188: Insecure Default Initialization of Resource","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/problemTypes/0/descriptions/0
Source references
12 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/07/29/9"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/adp/0/references/0
{"url":"http://www.openwall.com/lists/oss-security/2026/08/01/6"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/adp/0/references/2
{"url":"https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/adp/0/references/1
{"name":"https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e","tags":["x_refsource_MISC"],"url":"https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/1
{"name":"https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5","tags":["x_refsource_MISC"],"url":"https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/2
{"name":"https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a","tags":["x_refsource_MISC"],"url":"https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/3
{"name":"https://github.com/rails/rails/releases/tag/v7.2.3.2","tags":["x_refsource_MISC"],"url":"https://github.com/rails/rails/releases/tag/v7.2.3.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/4
{"name":"https://github.com/rails/rails/releases/tag/v8.0.5.1","tags":["x_refsource_MISC"],"url":"https://github.com/rails/rails/releases/tag/v8.0.5.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/5
{"name":"https://github.com/rails/rails/releases/tag/v8.1.3.1","tags":["x_refsource_MISC"],"url":"https://github.com/rails/rails/releases/tag/v8.1.3.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/6
{"name":"https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/0
{"name":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.yml","tags":["x_refsource_MISC"],"url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.yml"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/7
{"name":"https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html","tags":["x_refsource_MISC"],"url":"https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:49aa70e784da40c1014fa3b89efec9bf3b591e28ab747203c2f710d9db4bf6bc · sha256:a393eef13f9a6bab… · /containers/cna/references/8
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.