Dossier
Active Storage
Coverage of Active Storage in the Nexus archive.
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails has patched a critical Active Storage vulnerability (CVE-2026-66066) that could allow unauthenticated attackers to read arbitrary files from application servers via crafted image uploads. The flaw, rated with a CVSS score of 9.5, risks exposing sensitive data such as secret_key_base, Rails master key, database passwords, and cloud storage credentials.