CVE-2026-66066 is a critical vulnerability in Ruby on Rails Active Storage with a CVSS score of 9.5. It allows unauthenticated attackers to read arbitrary server files via crafted image uploads when using libvips. Affected versions include Rails 7.0.0 through 7.2.3.1, 8.0.0 through 8.0.5, and 8.1.0 through 8.1.3. Patches are available in versions 7.2.3.2, 8.0.5.1, and 8.1.3.1.