CVE

CVE-2026-66066

Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing

Exploitation IoCs 9

Domain canary
Domain corepack[.]org
Filename .bash_history
Filename .sysd
Filename /root/.cache/langflow/secret_key
Filename lib/.threadpool.rb
IP 165[.]154[.]236[.]93
IP France
IP Israel

MITRE ATT&CK TTPs 21

Source Articles

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-0768 in Langflow and CVE-2026-66066 (KindaRails2Shell) in Ruby on Rails, to conduct credential probing, remote code execution, and command-and-control activities. Exploitation of CVE-2026-66066 involves uploading a crafted image to read sensitive files, leak environment secrets, and achieve RCE, particularly when libvips is used for image processing. Attackers have targeted canary systems globally, with source traffic traced to Russia and a single IP in France, and C2 infrastructure in Israel. Additional post-exploitation activities include deploying credential harvesters, cryptominers, disabling auditd, and lateral movement.
hacker-news Sep 1, 2026
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
hacker-news Aug 3, 2026
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability, CVE-2026-66066, in the Rails Active Storage component allows unauthenticated attackers to read arbitrary files from a Rails application by uploading a specially crafted image when libvips is used for image processing. If successful, attackers can extract sensitive environment variables such as 'secret_key_base', enabling session forgery, data manipulation, and remote code execution (RCE). The vulnerability affects Active Storage versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1, with no workaround available for older libvips versions. Public proof-of-concept exploits have accelerated disclosure and prompted WAF protections from Akamai.
bleeping-computer Aug 1, 2026