CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-66066: Critical Active Storage Vulnerability in Ruby on Rails

July 29, 2026

CVE-2026-66066 is a critical vulnerability in Ruby on Rails Active Storage with a CVSS score of 9.5. It allows unauthenticated attackers to read arbitrary server files via crafted image uploads when using libvips. Affected versions include Rails 7.0.0 through 7.2.3.1, 8.0.0 through 8.0.5, and 8.1.0 through 8.1.3. Patches are available in versions 7.2.3.2, 8.0.5.1, and 8.1.3.1.