KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066)
Summary
The article discusses a critical RCE vulnerability (CVE-2026-66066) in Ruby on Rails Active Storage when using libvips. It enumerates affected Rails versions and config conditions, and outlines remediation steps including upgrading Rails and libvips and considering environment variable protections. It also notes that a WAF is not a replacement for patching.