A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).

A critical Active Storage vulnerability allows arbitrary file read and possible remote code execution through libvips variant processing. Here's what to check and how to patch.

CVE-2026-66066 could expose Rails server files through image uploads, leaking secrets that may enable RCE or lateral movement.