🚨 We discovered a critical RCE in Ruby on Rails via Active Storage.
KindaRails2Shell - discovered by the Ethiack research team.
Any app using Active Storage with the default vips processor and accepting image uploads from untrusted users is affected.
CVE-2026-66066
ethiack.com/info-hub/res...
ethiack.com
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack — Autonomous Ethical Hacking for continuous security
Ethiack research team discovered KindaRails2Shell (CVE-2026-66066): a critical RCE in Ruby on Rails via Active Storage. 500,000+ sites affected. Find out if you are and how to mitigate.