
Critical Rails Flaw Lets Attackers Read Arbitrary Files and Execute Malicious Code Remotely
A severe security vulnerability in Ruby on Rails Active Storage tracked as CVE-2026-66066 can let unauthenticated attackers read sensitive files from a server and potentially escalate to remote code execution. The issue affects applications that use libvips for image variant processing and accept image uploads from untrusted users, putting secrets such as secret_key_base, cloud credentials, […]
The post Critical Rails Flaw Lets Attackers Read Arbitrary Files and Execute Malicious Code Remotely appeared first on Cyber Security News.