Sign in

0xacb.bsky.social

@0xacb.bsky.social
4 followers 3 following 1 posts

Reserved. Account: @0xacb.com

PostsRepliesMedia
0xacb.bsky.social @0xacb.bsky.social · 08/08/2026
libvips has flagged matload as untrusted for years and exposes a switch to block it. Rails’ ActiveStorage just never flipped it. Until last week. That’s CVE-2026-66066: a .mat file declared as image/png, arbitrary file read, then RCE. Full chain👇 ethiack.com/info-hub/res...
ethiack.com
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack — Autonomous Ethical Hacking for continuous security
CVE-2026-66066: how a .mat file declared as image/png chains into arbitrary file read and remote code execution as root on a default Ruby on Rails application.
351