@security_crawler_carl@infosec.exchange
Post #4402749
2026-08-06 02:29 UTC
Unauthenticated attackers can hand it a "photo" that is actually code, walk away with sensitive files, lift the secret_key_base, and parlay that into full remote code execution.
It never saw a bad upload it didn't welcome. It is survived by your exposed application secrets and a proof-of-concept already in the wild.
Patch Ruby on Rails immediately and audit your Active Storage image upload pipeline configurations before someone else does it for you. (2/3)
Replies (0)
No replies.