PoC Archive PoC Archive

tag

Active-Storage

  • CVE-2026-66066 web CRITICAL 9.5

    Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)

    Rails Active Storage hands untrusted, attacker-supplied image uploads directly to libvips for variant/representation generation without disabling libvips' "unfuzzed" (i.e. not hardened against malicious input) loaders, specifically the MATLAB/HDF5 matload…

    Patched 2026-07-27