Rails Active Storage Flaw Enables Arbitrary File Read, Possible RCE via libvips (CVE-2026-66066)
A critical Rails Active Storage flaw (CVE-2026-66066) lets attackers read arbitrary server files via crafted image uploads processed by libvips, potentially exposing secrets and enabling RCE. Patch activestorage and libvips >= 8.13, and rotate exposed credentials now.