This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
FastRuby.io
fastruby.io
did:plc:2nka6vsspwyeczmkgkgi6k4u
Critical Rails CVE-2026-66066: file read + RCE in Active Storage vips image processing (default since Rails 7.0).
Patch today: 7.2.3.2 / 8.0.5.1 / 8.1.3.1.
On 7.1 or older? No patch. Set VIPS_BLOCK_UNTRUSTED (libvips 8.13+) and plan your upgrade.
Need a hand? fastruby.io/#contactus
https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432
2026-07-30T15:02:26.668Z