Skip to content

Commit 70a75b9

Browse files
authored
Merge pull request #1189 from jasnow/rails-adv
One new activestorage gem advisory @flavorjones - Thanks for reviewing and approvinig my PR.
2 parents c221da6 + 85a03e2 commit 70a75b9

1 file changed

Lines changed: 73 additions & 0 deletions

File tree

Lines changed: 73 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
---
2+
gem: activestorage
3+
framework: rails
4+
cve: 2026-66066
5+
ghsa: xr9x-r78c-5hrm
6+
url: https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-66066
7+
title: Possible arbitrary file read and remote code execution in
8+
Active Storage variant processing
9+
date: 2027-07-29
10+
description: |
11+
## Impact
12+
13+
In its default configuration, a Rails application that displays image
14+
variants may allow an unauthenticated attacker to read arbitrary files
15+
from the server, including the process environment. That environment
16+
typically holds secret_key_base and often credentials for external
17+
systems, which may in turn allow escalation to remote code execution
18+
or lateral movement to those systems.
19+
20+
## Affected applications
21+
22+
An application is affected if it meets all of these requirements:
23+
24+
* Uses libvips for Active Storage image processing. This is
25+
config.active_storage.variant_processor = :vips, which
26+
load_defaults 7.0 set and no later default has changed.
27+
* Allows image uploads from untrusted users.
28+
Generating variants is not a separate requirement.
29+
30+
## Workarounds
31+
32+
If libvips < 8.13 is being used, there are no workarounds available
33+
other than removing the dependency on libvips from the application.
34+
Some applications may have ruby-vips declared as a dependency only
35+
for image analysis, and those applications may be able to simply
36+
remove ruby-vips from the Gemfile to remove libvips from the
37+
application. Applications that do not use Active Storage can remove
38+
ruby-vips from the Gemfile to avoid the boot-time checks.
39+
40+
If libvips >= 8.13 is present on the system, applications can disable
41+
the unfuzzed operations without upgrading Rails by setting the
42+
VIPS_BLOCK_UNTRUSTED environment variable, which libvips reads while
43+
initializing.
44+
45+
Applications also running ruby-vips >= 2.2.1 or later can instead call
46+
Vips.block_untrusted(true) from an initializer.
47+
48+
## Credit
49+
50+
This issue was responsibly reported by 0xacb, s3np41k1r1t0 and castilho
51+
from Ethiack, and RyotaK from GMO Flatt Security Inc..
52+
cvss_v4: 9.5
53+
patched_versions:
54+
- "~> 7.2.3.1"
55+
- "~> 8.0.5.1"
56+
- ">= 8.1.3.1"
57+
related:
58+
url:
59+
- https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-66066
60+
- https://rubygems.org/gems/activesupport/versions/8.1.3.1
61+
- https://github.com/rails/rails/releases/tag/v8.1.3.1
62+
- https://rubygems.org/gems/activesupport/versions/8.0.5.1
63+
- https://github.com/rails/rails/releases/tag/v8.0.5.1
64+
- https://rubygems.org/gems/activesupport/versions/7.2.3.2
65+
- https://github.com/rails/rails/releases/tag/v7.2.3.2
66+
- https://blog.flatt.tech/entry/kindarails2shell_rails
67+
- https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve
68+
- https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm
69+
notes: |
70+
- CVE is reserved, but not published.
71+
- cvss_v4 from project GHSA
72+
- From GHSA: "Details will be disclosed no later than 2026-08-28,
73+
via the Rails Security Announcements forum."

0 commit comments

Comments
 (0)