CVE-2026-66066 – Rails

CVSS 9.5 CRITICAL Zero Day – Immediate Deployment

“A crafted image upload can expose application secrets and open the door to deeper compromise.”

Rails fixed a critical Active Storage vulnerability affecting applications that use libvips and accept untrusted image uploads. CVE-2026-66066 allows an unauthenticated attacker to trigger unsafe libvips processing and read arbitrary files accessible to the Rails process, including environment variables and application secrets. The CVSS score is 9.5, which is Critical severity.

Public proof-of-concept material is available. The issue is fixed in Rails versions 7.2.3.2, 8.0.5.1, and 8.1.3.1.

Key Details

CWE Classification
CWE-1188
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.