Ruby on Rails is an open-source web application framework. A critical vulnerability in its Active Storage component, CVE-2026-66066, allows unauthenticated file reads via image uploads. Patches have been released for affected versions.
Ruby on Rails is an open-source web application framework. A critical vulnerability in its Active Storage component, CVE-2026-66066, allows unauthenticated file reads via image uploads. Patches have been released for affected versions.