• Sources: rails/rails-forensics-CVE-2026-66066, Rails security announcement
  • Summary: The Rails organization published an MIT-licensed documentation and skill repository for CVE-2026-66066, the Active Storage and libvips arbitrary file read the reporters named KindaRails2Shell, and the repository states the method came out of a real investigation at 37signals sweeping a large production Active Storage store, and that it identified the test files uploaded by the reporting researchers. It traces the chain as follows: a direct upload lets the client set the content_type column without the bytes being examined, libvips then sniffs magic bytes, a file whose first ten bytes claim MATLAB 5.0 routes to the libvips MATLAB loader, libmatio dispatches on a different byte range and finds MAT 7.3, which is HDF5, and HDF5's External File List lets a dataset's bytes live in another file named by path and offset, so rendering the variant reads an attacker-chosen file and returns its contents as pixel values. Two skills produce an exposure window and then a forensic analysis, the detector reads two header fields from the first 128 bytes of an object so a candidate is classified from a ranged read, and no payload generator and no crafted files are shipped. The repository README directs operators to take the patched version numbers from the advisory, which lists the affected versions as activestorage below 7.2.3.2, activestorage from 8.0 and below 8.0.5.1, and activestorage from 8.1 and below 8.1.3.1. The same advisory states that libvips must be upgraded to 8.13 or later, because Active Storage raises an exception at boot on libvips below 8.13, which cannot disable unfuzzed operations at all.
  • Why it matters: The 2026-07-29 advisory told operators to patch and rotate secrets but gave them nothing to answer whether they were exploited, and Active Storage on the vips variant processor has been the load_defaults 7.0 default with no later default changing it.
  • Follow-up: The repository covers Active Storage where variant records were tracked and not other paths that hand user files to libvips, and the 2026-07-29 advisory said technical details would be disclosed no later than 2026-08-28, so track what that disclosure adds.

send feedback on this story