Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xr9x-r78c-5hrm | Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing |
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rails
Rails rails |
|
| Vendors & Products |
Rails
Rails rails |
Thu, 30 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1. | |
| Title | Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing | |
| Weaknesses | CWE-1188 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-30T19:16:14.471Z
Reserved: 2026-07-23T23:25:28.897Z
Link: CVE-2026-66066
Updated: 2026-07-30T18:35:38.631Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T20:26:05Z
-
CWE-1188
Initialization of a Resource with an Insecure Default
Github GHSA