Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
2026-08-04T07:23:38Z•28322c4db08c18c59335f6ab33ad6a34eaa1b29c7c37331c1b5246a9bedb43fb
CVE-2026-66066Active StorageCWE-1188KindaRails2ShellRuby on RailsVipsarbitrary file readlibvipsremote code executionunauthenticateduntrusted uploadsweb application
What happened
Rapid7 details CVE-2026-66066 (KindaRails2Shell), a critical unauthenticated arbitrary file read in Ruby on Rails Active Storage applications using libvips/Vips to process untrusted uploads. Exploitation can expose Rails secrets and potentially enable remote code execution or access to connected systems. Affected versions include Active Storage before 7.2.3.2, 8.0 before 8.0.5.1, and 8.1 before 8.1.3.1; Rails 6 is affected when Vips is explicitly configured. The vulnerability is rated CVSS 4.0 9.5.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 28322c4db08c18c59335f6ab33ad6a34eaa1b29c7c37331c1b5246a9bedb43fb
- Enrichment time
- 2026-08-04T07:23:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.