Patching Rails against KindaRails2Shell only works if the libvips underneath it is new enough
2026-09-01Security
CVE-2026-66066 leaks the Rails master key to an unauthenticated attacker who uploads an image. The fix ships in Active Storage — but it works by calling into libvips, so a gem upgrade on an old system library may not deliver it. Exploitation started roughly a month after the patch.