Skip to main content
QUIETLYTIC
Vulnerability

Ruby on Rails / Action Pack Vulnerability (CVE-2026-66066)

CVE-2026-66066 is an unauthenticated arbitrary file read in Rails Active Storage via unsafe libvips operations, per VulnCheck.

CVE-2026-66066
Threat Level
NOT YET SCORED
CVSS
—
Status
Active Exploitation
Confidence
Medium
Affected Products
Ruby on Rails / Action Pack (before 7.2.3.2, 8.0.5.1, 8.1.3.1)

CVE-2026-66066 affects Ruby on Rails’ Action Pack framework, specifically Active Storage, in versions before 7.2.3.2, 8.0.5.1, and 8.1.3.1. NVD classifies it as CWE-1188 (Initialization of a Resource with an Insecure Default). Our source data does not carry a CVSS score for this CVE as of our ingestion. VulnCheck’s KEV feed reports the CVE as exploited, dated August 25, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-66066 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

Per NVD, Active Storage does not disable libvips image-processing operations that are marked unsafe for untrusted content, allowing a crafted file upload to invoke one of those unsafe operations. Applications are affected when configured to use libvips as their image-processing backend and when they accept image uploads from untrusted users. NVD states an unauthenticated attacker can exploit this to read arbitrary files accessible to the Rails process — including environment variables and application secrets — and that exposure of credentials such as secret_key_base or external-service tokens can in turn enable remote code execution or lateral movement.

Evidence and confidence

  • Medium confidence — the CWE-1188 classification and the described mechanism trace to NVD alone in our current ingestion, corroborated by Rails’ own GitHub Security Advisory (GHSA-xr9x-r78c-5hrm) and reporting from The Hacker News. The exploitation report traces to VulnCheck KEV alone.
  • Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.27861, a 98.0th percentile score as of our ingestion, among the highest in this entire batch of KEV additions.

No field is in conflict between our sources.

Why this matters

The chain NVD describes — an unauthenticated file-read primitive escalating to secret exposure escalating to potential remote code execution — is a full application-compromise path, not an isolated information-disclosure bug, and it lands squarely in a default-adjacent configuration: any Rails application using Active Storage with libvips and accepting untrusted image uploads is in scope. The near-98th-percentile EPSS score is one of the strongest exploitation-probability signals we’ve reported in this KEV batch, consistent with the severity of what NVD describes as the practical outcome. Rails applications matching this configuration should treat upgrading to 7.2.3.2, 8.0.5.1, or 8.1.3.1 as urgent, and should rotate secret_key_base and any exposed external-service tokens if there is reason to believe the flaw was exploited before patching.

Frequently Asked Questions

What is CVE-2026-66066? An unauthenticated arbitrary file read vulnerability (CWE-1188) in Rails Active Storage before versions 7.2.3.2, 8.0.5.1, and 8.1.3.1, arising from unsafe libvips operations not being disabled for untrusted content, with a path to secret exposure and potential remote code execution.

Is CVE-2026-66066 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 25, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated attacker, provided the application accepts untrusted image uploads and uses libvips for processing.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Rails/Action Pack 7.2.3.2, 8.0.5.1, or 8.1.3.1, per NVD and Rails’ own GitHub Security Advisory.


Weakness classification and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-66066, corroborated by Rails’ own GitHub Security Advisory and The Hacker News coverage. Exploitation status and the August 25, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools