Vulnerability threat dossier

CVE-2026-66066

railsrails

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

VTP deterministic threat46.6of 100 · CVSS excluded

VTP analyst assessment

Rails Active Storage unsafe image processing

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence90%
Public exploitation · VTP factCONFIRMED

Assessment

VulnCheck, as reported by The Hacker News, found attackers exploiting CVE-2026-66066. Crafted image uploads can invoke libvips operations unsafe for untrusted content when Active Storage uses libvips.

Why it matters

  • The attack requires an application to accept untrusted image uploads and use libvips.
  • Successful exploitation could disclose files, obtain secrets, and lead to remote code execution, according to SecurityWeek.

Evidence

5 record references and 4 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

Public reporting does not identify affected application versions or the exact exploitation sequence.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Rails Active Storage with libvips and untrusted uploads, upgrade to 7.2.3.2, 8.0.5.1, 8.1.3.1, or later.

AI baseline history (6)
  1. BASELINE ASSESSED
    Rails Active Storage unsafe image processinggpt-5.6-terra · low
  2. BASELINE ASSESSED
    Rails Active Storage unsafe libvips operationgpt-5.6-sol · high
  3. BASELINE ASSESSED
    Rails Active Storage unsafe libvips operationsgpt-5.6-sol · high
  4. BASELINE ASSESSED
    Rails Active Storage unsafe libvips operationgpt-5.6-sol · high
  5. BASELINE ASSESSED
    Rails Active Storage libvips exploitation and toolinggpt-5.6-sol · high
  6. BASELINE ASSESSED
    Critical Rails image-processing flaw with reported exploitationgpt-5.6-sol · high

Previous AI priority: HIGH → current: HIGH. Inspect the evidence preserved for each run before treating this as a threat transition.

Technical severityCRITICALCVSS 9.5 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.2898th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A primary source reports active exploitation.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.28; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

RESEARCH PUBLICATIONNew technical research
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
RESEARCH PUBLICATIONNew technical research
ACTIVE EXPLOITATIONActive Exploitation
POC AVAILABLEPoc Available
RESEARCH PUBLICATIONNew technical research
03

Claim provenance

Evidence and source independence

6publications detected
6underlying evidence chains

1 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:50c9f86535ee8f26cef816ce0f2944b8f074e4008a851e616d1c8ad5174bd271ACTIVE
Evidence
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:METASPLOIT:c660622f01fed74e78a3a6637b17e8abe0ec7e20ACTIVE
Evidence
Source claimACTIVE EXPLOITATIONSOURCE REPORTS ACTIVE EXPLOITATION
82%claim confidence
INDEPENDENTreport:98345c78aa6e59f56dc2426587fad7dff075f1227ab73cad0b842c28454debfcACTIVE
Evidence
Source claimPOC AVAILABLEPUBLICATION REPORTS POC
78%claim confidence
INDEPENDENTreport:98345c78aa6e59f56dc2426587fad7dff075f1227ab73cad0b842c28454debfcACTIVE
Evidence
04

Event history

Threat timeline

  1. 07:2201 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 14:5728 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-66066.

  3. 03:3126 Aug
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Rapid7 Metasploit Framework published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  4. 17:1103 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-66066.

  5. 16:1130 Jul
    ACTIVE EXPLOITATION

    Active Exploitation

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

  6. 16:1130 Jul
    POC AVAILABLE

    Poc Available

    Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

  7. 16:1130 Jul
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-66066.

05

Original publications

Source record

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

CVE-2025-3248CVE-2026-0768CVE-2026-0769CVE-2026-5027CVE-2026-66066
Separate evidence group
Original

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely. The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .

CVE-2026-66066
Separate evidence group
Original

Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

CVE-2026-0265CVE-2026-16232CVE-2026-19681CVE-2026-21820CVE-2026-3576CVE-2026-56274CVE-2026-59774CVE-2026-60137CVE-2026-63030CVE-2026-66066CVE-2026-6826CVE-2026-9082CVE-2026-9198
Separate evidence group
Original

Exploit tooling coverage expanded for 2 CVEs

Rapid7 Metasploit Framework added or materially changed exploit-oriented artifacts covering 2 CVEs. This establishes public tooling availability; it does not establish exploitation in the wild or successful execution.

CVE-2025-24293CVE-2026-66066
Separate evidence group
Original

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2 , >= 8.0, < 8.0.5.1 , and >= 8.1, < 8.1.3.1 . Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips. Our Emergent Threat Response blog covers the affected versions, mitigation guidance, and current exploitation status. This post traces the request from the direct-upload endpoint to the HDF5 read, then shows how the arbitrary file read can expose Rails signing material and become code execution. A vulnerable application can disclose arbitrary files before the attacker has recovered a Rails secret or forged a token. A genuine Active Storage variation_key from the same application, paired with a direct-upload blob whose stored content_type claims to be an image, is enough to reach a libvips loader that turns a crafted MAT/HDF5 file into an arbitrary file-read oracle. We reproduced the published chain against Rails 6.0.6.1 , 6.1.7.10 , 7.2.3.1 , 8.0.5 , and 8.1.3 , and confirmed that patched 7.2.3.2 , 8.0.5.1 , and 8.1.3.1 targets block the crafted representation. We also validated a remote code execution (RCE) path that uses only JSON-compatible Hash , Array , and String values in a signed variation. That path reaches Kernel#spawn or Kernel#eval through ImageProcessing's chain builder, and it worked when Rails was configured with config.active_support.message_serializer = :json . The advisory covers the vulnerable Active Storage configuration. The MAT/HDF5 representation chain shown here has narrower requirements. The deployed libvips build must expose matload with MAT 7.3/HDF5 support, the application must preserve an attacker-supplied content_type , and the attacker must be able to trigger a representation, for example with a genuine variation key. Those requirements narrow where this particular chain works, but the underlying issue is that Active Storage handed untrusted uploads to libvips operations that libvips already marked unsafe for untrusted content. The attack can be summarized as follows: [Attacker] | | 1. Creates a direct-upload blob with content_type = image/png v [Rails stores the blob as an image without examining the bytes] | | 2. Reuses a genuine variation_key from the same application v [Rails accepts the blob as variable and starts a representation] | | 3. image_processing hands the local tempfile path to libvips v [libvips matload] | | 4. Bytes 0-9 match "MATLAB 5.0" v [libmatio] | | 5. Bytes 124-125 contain MAT_FT_MAT73 (0x0200) v [HDF5 external storage] | | 6. Dataset bytes come from attacker-chosen path + offset v [Rendered PNG representation] | --> Target file bytes are returned as image pixels Analysis The published chain contains two separate trust failures. Rails decides that a blob is an image from a database value, while libvips decides what parser to use from the bytes on disk. Once the file reaches matload , libvips and libmatio disagree again about the same MAT header. libvips only looks at the first ten bytes, while libmatio selects the MAT version from bytes 124 and 125. Direct upload stores an attacker-controlled type The standard direct-upload endpoint creates the blob record before the service receives the file. In Rails 8.0.5 , ActiveStorage::DirectUploadsController#create accepts content_type directly from the request and passes it into create_before_direct_upload! : class ActiveStorage::DirectUploadsController < ActiveStorage::BaseController def create blob = ActiveStorage::Blob.create_before_direct_upload!(**blob_args) # <-- [1] render json: direct_upload_json(blob) end private def blob_args params.expect(blob: [:filename, :byte_size, :checksum, :content_type, metadata: {}]).to

CVE-2026-66066
Separate evidence group
Original

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of a Resource with an Insecure Default ( CWE-1188 ). An unauthenticated attacker may be able to leverage CVE-2026-66066 and read files accessible to the Rails application process, potentially exposing secrets that could enable remote code execution (RCE) or access to connected systems. An application is affected when it uses libvips for Active Storage image processing and accepts image uploads from untrusted users. Rails notes that generating image variants is not a separate requirement for exposure. Vips is the default Active Storage variant processor for applications configured with Rails 7.0 or later defaults. According to Ethiack , only the Vips processor is affected; applications using Magick are not affected through the reported vector. As of July 30, 2026, Rapid7 is not aware of exploitation in the wild. Ethiack and GMO Flatt Security, who independently reported the vulnerability, have withheld proof-of-concept code and details of the full attack chain. Public code claiming to exploit CVE-2026-66066 exists, but it is unclear how closely it corresponds to the full attack chain reported privately to Rails. According to the Rails Security Announcement , additional details will be disclosed no later than August 28, 2026. Rapid7 recommends remediating affected applications on an urgent basis, outside of normal patch cycles. Update #1 : On July 31, 2026, Rails published technical details and forensic tools earlier than its planned August 28 disclosure date after several researchers reverse-engineered the attack and published proof-of-concept code. Technical overview libvips uses operations to load and save image formats, including operations backed by third-party libraries. Some are marked "unfuzzed" or "untrusted" because they are unsafe for untrusted content. According to Rails, Active Storage did not disable these operations before processing user-supplied files, which may allow a crafted upload to trigger an unsafe operation and disclose files readable by the application. The attack details published by Rails describe a chain in which an attacker creates a blob through Active Storage's direct-upload endpoint with a false image content type and obtains a genuine signed variation_key from a page that renders an Active Storage representation. A crafted file identifies itself to libvips as a MATLAB level 5 file but to libmatio as a MAT 7.3 HDF5 container. HDF5's External File List then reads bytes from an attacker-selected path, which are rendered as image pixels and returned in the resulting variant. This known chain also requires the deployed libvips build to include the matload operation. For this documented chain, the Active Storage direct-upload route must be reachable. When Active Storage routes are mounted, the direct-upload route is present by default even if the application's own interface does not use direct uploads. Rapid7 testing found that ordinary server-side attachment does not satisfy this chain because Rails re-identifies the crafted file as MATLAB data before variant processing. The arbitrary file-read stage does not require knowledge of secret_key_base or a forged variation key. Rapid7 also verified an RCE escalation in which recovered Rails signing material is used to forge an ImageProcessing 1.x variation; this path does not require Marshal deserialization. The Rails patch that remediates CVE-2026-66066, disables untrusted operations during Active Storage initialization. When ruby-vips is installed, patched versions prevent the application from starting if ruby-vips or libvips is too old to support that protection. On August 3, 2026, Rapid7 Labs published a full root cause technical analysis

CVE-2026-66066
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score46.6vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction5.57 / 20
Exploit availability7.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.5 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-1188
CPE records
0
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.