
Software
A booby-trapped image upload can now steal your Rails app's secret keys — no login needed
CVE-2026-66066 scores a 9.5 on CVSS 4.0 because Active Storage's image pipeline can be tricked into reading any file the app can read, no authentication required.
Priya Nair · 2h ago · 7 min