Critical Rails Flaw Could Expose Server Files
Cybersecurity

Critical Rails Flaw Could Expose Server Files

Published:
Updated:

Ruby on Rails has released fixes for a critical vulnerability in Active Storage that could allow unauthenticated attackers to read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066, the flaw has a CVSS score of 9.5. Exploitation could expose the Rails process environment and secrets including secret_key_base, the Rails master key, database passwords, cloud storage credentials and API tokens. Those secrets could enable remote code execution or lateral movement into connected systems. Ethiack and GMO Flatt Security identify the affected ranges as Rails 7.0.0 through 7.2.3.1, Rails 8.0.0 through 8.0.5, and Rails 8.1.0 through 8.1.3. Rails 6.0.0 through 6.1.7.10 are affected only when Active Storage is configured to use Vips, which was not the default processor in Rails 6. Why it matters for Somali readers: Administrators running affected Rails versions should apply the fixes promptly to protect server secrets and connected systems.

Source: Thehackernews

Read our sourcing and corrections policy

Share:

Comments

Be the first to comment on this story!