Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

2026-08-03T19:23:37Zb2aec62cb97f7750ad865719df81d920936c54f08e1415cee521deaf63e70bc8
CVE-2026-66066Active StorageHTTP MeterpreterMetasploitRuby on RailsVipsarbitrary file readcritical vulnerabilitylibvipsmalleable C2remote code executionunauthenticateduntrusted file uploadvulnerability

What happened

Rapid7 reports CVE-2026-66066, a critical unauthenticated arbitrary file read in Ruby on Rails Active Storage applications using libvips/Vips with untrusted uploads. Affected versions include Rails Active Storage <7.2.3.2, 8.0.x <8.0.5.1, and 8.1.x <8.1.3.1; Rails 6 is affected only when Vips is explicitly configured. Exploitation may expose Rails signing secrets and potentially enable remote code execution or access to connected systems. CVSS v4 is 9.5. Other feed items describe Metasploit 6.5 and Pro 5.1 releases, including malleable HTTP(S) C2 profiles, plus Rapid7 business and event news.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
b2aec62cb97f7750ad865719df81d920936c54f08e1415cee521deaf63e70bc8
Enrichment time
2026-08-03T19:23:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.