Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
2026-08-03T19:23:37Z•b2aec62cb97f7750ad865719df81d920936c54f08e1415cee521deaf63e70bc8
CVE-2026-66066Active StorageHTTP MeterpreterMetasploitRuby on RailsVipsarbitrary file readcritical vulnerabilitylibvipsmalleable C2remote code executionunauthenticateduntrusted file uploadvulnerability
What happened
Rapid7 reports CVE-2026-66066, a critical unauthenticated arbitrary file read in Ruby on Rails Active Storage applications using libvips/Vips with untrusted uploads. Affected versions include Rails Active Storage <7.2.3.2, 8.0.x <8.0.5.1, and 8.1.x <8.1.3.1; Rails 6 is affected only when Vips is explicitly configured. Exploitation may expose Rails signing secrets and potentially enable remote code execution or access to connected systems. CVSS v4 is 9.5. Other feed items describe Metasploit 6.5 and Pro 5.1 releases, including malleable HTTP(S) C2 profiles, plus Rapid7 business and event news.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- b2aec62cb97f7750ad865719df81d920936c54f08e1415cee521deaf63e70bc8
- Enrichment time
- 2026-08-03T19:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.