Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
The Hacker News
1 week ago

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

By info@thehackernews.com (The Hacker News)

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.