libvips has flagged matload as untrusted for years and exposes a switch to block it. Rails’ ActiveStorage just never flipped it. Until last week.
That’s CVE-2026-66066: a .mat file declared as image/png, arbitrary file read, then RCE.
Full chain👇
ethiack.com/info-hub/res...
ethiack.com
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack — Autonomous Ethical Hacking for continuous security
CVE-2026-66066: how a .mat file declared as image/png chains into arbitrary file read and remote code execution as root on a default Ruby on Rails application.