chiprook
← Security
SecuritySeptember 26, 2026, 17:20

CVE-2026-66066: Rails avatar upload reads /proc/self/environ

Ruby on Rails vulnerability CVE-2026-66066, scored 9.5, lets an image upload read /proc/self/environ when Active Storage uses libvips older than 8.13, exposing SECRET_KEY_BASE. That enables forged signed variant parameters and command execution. Fixes are Rails 7.2.3.2, 8.0.5.1 and 8.1.3.1 plus Vips.block_untrusted = true.

CVE-2026-66066: Rails avatar upload reads /proc/self/environ
#Rails#Libvips#ActiveStorage
Read next
Security

Z.ai open-sources ZCode after secretly uploading users' code encrypted

Security

Zhipu says ZCode removed repository-upload paths after data controversy

Security

Z.ai silently uploaded devs' local data: 313MB and 564 upload attempts

Security

AI Coding App ZCode Found Silently Uploading Entire Git History