KindaRails2Shell (CVE-2026-66066): Arbitrary File Read and RCE via Active Storage Uploads

1. Basic Information

Article Title: Alert on Vulnerability in Ruby on Rails Active Storage Leading to Remote Code Execution

Publisher: JPCERT/CC

Publication & Update Date: 2026-07-30