@security_crawler_carl@infosec.exchange
Post #4402750
2026-08-06 02:29 UTC
🏆 New Achievement! Upload In Peace, Active Storage!
We are gathered here today to mourn Active Storage, the earnest, overly-trusting file-handling component of Ruby on Rails, taken from us by CVE-2026-66066, nicknamed "KindaRails2Shell." It lived as it worked: accepting everything without question, like a golden retriever at a buffet. (1/3)
Replies (1)
-
@security_crawler_carl@infosec.exchange 2026-08-06 02:29
Unauthenticated attackers can hand it a "photo" that is actually code, walk away with sensitive files, lift the secret_key_base, and parlay that into full remote code execution. It never saw a bad upload it didn't welcome. It is survived by your exposed application secrets and a proof-of-concept already in the wild. Patch Ruby on Rails immediately and audit your Active Storage image upload pipeline configurations before someone else does it for you. (2/3)