VDB
CVE-2026-66066
CVE-2026-66066
PUBLISHED
Ruby on Rails ist ein in der Programmiersprache Ruby geschriebenes und quelloffenes Web Application Framework.
EPSS 1.77% · 75.9th percentile
Risk Scores
EPSS Score
1.77%
75.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source | Open Source Ruby on Rails libvips <8.13 | |
| Open Source | Open Source Ruby on Rails <7.2.3.2 | |
| Open Source | Open Source Ruby on Rails <8.1.3.1 | |
| Open Source | Open Source Ruby on Rails <8.0.5.1 |
Timeline
- Jul 29, 2026 CVE Published
- Jul 31, 2026 Coalition ESS Score
- Jul 31, 2026 Security Advisory
- Aug 5, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
References
- https://github.com/rapid7/metasploit-framework/pull/21733 fix
- https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2574.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2574 advisory
- https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432 advisory
- https://rubyonrails.org/2026/7/29/Rails-Versions-7-2-3-2-8-0-5-1-and-8-1-3-1-have-been-released advisory
- https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm advisory