CVE-2026-66066 scores a 9.5 on CVSS 4.0 because Active Storage's image pipeline can be tricked into reading any file the app can read, no…
The short version
The short version
The short version
The short version
The short version
Why 9.5 is the right number
Aliteq
A booby-trapped image upload can now steal your Rails app's secret keys — no login needed