Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Title source: cnaExploitation Summary
EIP tracks 4 public exploits for CVE-2026-66066. PoCs published by Zer0SumGam3, rails, paveg.
AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2026-66066, a Rails Active Storage file-read-to-RCE chain exploiting unsafe deserialization in libvips image processing. The exploit constructs a malicious HDF5/MATLAB external-storage image with an embedded Ruby Marshal payload to leak SECRET_KEY_BASE and achieve remote code execution via MiniMagick::Tool.
Description
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.
Exploits (4)
This repository provides a functional proof-of-concept for CVE-2026-66066, a Rails Active Storage file-read-to-RCE chain exploiting unsafe deserialization in libvips image processing. The exploit constructs a malicious HDF5/MATLAB external-storage image with an embedded Ruby Marshal payload to leak SECRET_KEY_BASE and achieve remote code execution via MiniMagick::Tool.
This repository contains forensic tools to detect and analyze exploitation of CVE-2026-66066, a vulnerability in Ruby on Rails' Active Storage component involving libvips and libmatio. The tools scan for crafted MAT files that exploit an external file read issue in HDF5 containers, but do not contain exploit code.
This repository contains a configuration audit script for CVE-2026-66066, a vulnerability in Ruby on Rails' Active Storage component when using libvips as the variant processor. The script collects evidence to determine if a Rails application is exposed to arbitrary file read and remote code execution via unsafe libvips operations, but does not exploit the vulnerability.
This repository provides a high-level overview of CVE-2026-66066, a pre-authentication RCE vulnerability in Ruby on Rails Active Storage when processing images with libvips. However, it lacks exploit code, technical depth, or proof-of-concept details, serving only as a placeholder for documentation and detection rules.
References (10)
Scores
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X