
Critical RCE Vulnerability in Rails Active Storage via libvips (CVE-2026-66066)
CybersecurityVulnerabilitiesExploitsWebSecurityRailsActiveStorage
A vulnerability in Rails Active Storage’s default vips variant processor allows arbitrary file reading, which can be chained to achieve remote code execution (RCE) on Rails 7.x and 8.x. The issue affects applications serving processed variants of user-uploaded images and may not require authentication in some configurations. Only the vips processor is impacted; Magick is unaffected. Patches are available in Rails versions 7.2.3.2, 8.0.5.1, and 8.1.3.1, with libvips 8.13+ required for the fix.