What is CVE-2026-66066?
The KindaRails2Shell vulnerability (CVE-2026-66066) allows arbitrary file read in Ruby on Rails Active Storage when using the Vips image processor with untrusted uploads. Affected versions include those prior to 7.2.3.2, between 8.0 and 8.0.5.1, and early 8.1 releases. Administrators are urged to apply the security patches immediately.
Azərbaycanca: KindaRails2Shell (CVE-2026-66066) zəifliyi Ruby on Rails-in Active Storage komponentində, xüsusilə Vips prosessorundan istifadə edərkən etibarsız fayl yükləmələri vasitəsilə ixtiyari fayl oxumağa imkan verir. Təsirə məruz qalan versiyalar 7.2.3.2-dən əvvəl, 8.0-8.0.5.1 arası və 8.1-in ilkin versiyalarıdır. İnzibatçılara təcili olaraq təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which component of Ruby on Rails does the KindaRails2Shell vulnerability affect?
This vulnerability affects the Active Storage component of Ruby on Rails, specifically when using the Vips image processor.
What should administrators do to protect against the CVE-2026-66066 vulnerability?
Administrators are urged to apply the security patches immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.