Critical Remote Code Execution Vulnerability (CVE-2026-66066) Disclosed in Ruby on Rails

European cybersecurity firm Ethiack has revealed a critical remote code execution (RCE) vulnerability, dubbed KindaRails2Shell (CVE-2026-66066), in Ruby on Rails versions 7.x and 8.x. The flaw, found in the framework's default image processing component, allows attackers to read sensitive files, execute malicious code, and potentially take full control of affected servers when users upload images. Ethiack followed a responsible disclosure process, and an official security advisory with a CVSS score of 9.5 is now available.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai