Rails Patches Critical Active Storage RCE Vulnerability
Ruby on Rails has released patches for a critical vulnerability in its Active Storage framework, tracked as CVE-2026-66066 (CVSS 9.5). This flaw allows unauthenticated attackers to read arbitrary files from a Rails application through specially crafted image uploads. The vulnerability could potentially lead to remote code execution (RCE) by exposing sensitive information such as application secrets, database passwords, and cloud storage credentials.