- Sources: Rails security announcement, GHSA-xr9x-r78c-5hrm, Ethiack research
- Summary: Rails disclosed CVE-2026-66066 on 2026-07-29, a possible arbitrary file read and remote code execution in Active Storage variant processing. The announcement, bylined Rafael Franca, covers Rails 7.0 through 7.2.3.1 and 8.0 through 8.1.3 in their default configuration, because
load_defaults 7.0 selected the vips variant processor and no later default changed it. Rails 6.x is affected only under a non-default Active Storage configuration, and the Magick processor is not affected by this vector. Remediation is three steps rather than a gem bump: upgrade Active Storage to a fixed version, run libvips 8.13 or later because Active Storage now raises at boot below that, and rotate every secret readable by the application process, starting with secret_key_base. Ethiack's write-up names the GHSA identifier, the per-branch fixed versions, and a VIPS_BLOCK_UNTRUSTED stopgap. Technical details of the exploitation chain are withheld until 2026-08-28. - Why it matters: vips ships in the official Rails Docker images and on Debian and Ubuntu, so a default Rails 7.x or 8.x application that accepts image uploads from untrusted users is exposed without authentication.
- Follow-up: Watch for the 2026-08-28 publication of the exploitation chain, and for exploitation reports against unpatched Active Storage deployments.
send feedback on this story