Post #4229041
2026-07-30 05:56 UTC
Are there any Ruby people with views on [CVE-2026-66066] ? The official release uses wording like "In a default configuration" but as far as I can see the exploit is down to using a specific method storing and user uploaded images and then doing something specific with them?
Image manipulation has always been a huge attack surface, it's the sort of thing I always would have put in its own backend or container.
Replies (0)
No replies.