CVE-2026-66066
Summary
A critical Ruby on Rails Active Storage flaw, scored CVSS 9.5, in which crafted image uploads can expose process environment variables and application secrets — including master keys, database credentials and cloud storage tokens.
Details
Active Storage is the framework component that handles uploaded files, and the reported trigger is a crafted image: the variant-processing path can be induced to read arbitrary files, which turns any application that accepts user uploads into a disclosure route for its own secrets. That is a worse outcome than a typical Rails RCE because the exposure is the credentials the application uses to reach everything else — the same class of blast radius as the environment-variable exfiltration seen across the 2026 npm supply-chain campaigns. Rails issued urgent patches; the first-party advisory is the Ruby on Rails security discussion for the CVE, cited below alongside the reporting.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-66066 |
| CVSS | 9.5 |
| Vendor / product | Ruby on Rails (Active Storage) |
| Reported in the digest | 2026-07-30 |
Related Pages
Sources: raw/digests/Cyber-Digest-2026-07-30.md