{"id":1826,"date":"2026-07-31T07:21:09","date_gmt":"2026-07-31T00:21:09","guid":{"rendered":"https:\/\/vncybers.vn\/hieu-ve-rails-active-storage-cve-2026-66066-upload-anh-lo-bi-mat-may-chu\/"},"modified":"2026-07-31T07:21:09","modified_gmt":"2026-07-31T00:21:09","slug":"understanding-rails-active-storage-cve-2026-66066-image-upload-server-secrets","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/hieu-ve-rails-active-storage-cve-2026-66066-upload-anh-lo-bi-mat-may-chu\/","title":{"rendered":"Understanding Rails Active Storage CVE-2026-66066: Why uploading images can reveal server secrets"},"content":{"rendered":"<p><strong>CVE-2026-66066<\/strong> is a critical vulnerability in Ruby on Rails Active Storage, tied to how applications process uploaded images with libvips. The notable issue is not a single upload form, but the trust boundary between user-supplied files, the image processor, and the secrets present in the application runtime environment.<\/p>\n<p>The Hacker News, citing the Rails Security Team, Ethiack, and GMO Flatt Security, reported that the flaw has a CVSS score of 9.5 and may allow an unauthenticated attacker to read arbitrary files from the application server under certain conditions. If the exposed files or environment variables contain <strong>secret_key_base<\/strong>, the master key, database passwords, cloud service tokens, or API keys, the risk can expand into session takeover, remote code execution, or lateral movement into other systems.<\/p>\n<h2>Where does the vulnerability occur?<\/h2>\n<p>Active Storage is Rails built-in mechanism for managing attachments, avatars, product images, profile photos, and image variants such as thumbnails or resized copies. From Rails 7 onward, many default configurations use <strong>Vips<\/strong> as the image processor. Vips relies on libvips, a powerful library for reading, transforming, and writing many file formats.<\/p>\n<p>The weakness appears when a Rails application uses libvips to process images from an untrusted source. According to the official Rails advisory, libvips has operations or loaders marked as unsuitable for hostile content. Before the patch, Active Storage did not fully block these operations, allowing a specially crafted file to trigger unexpected processing paths and read files accessible to the Rails process.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/07\/rails-active-storage-inline.jpg\" alt=\"Server infrastructure illustrating the risk of exposing Rails application secrets through uploaded image processing\" style=\"max-width: 100%; height: auto;\" \/><\/p>\n<h2>Conditions for exposure<\/h2>\n<p>Not every Rails website is automatically exploitable. An application is usually in the risk zone when it uses Active Storage with libvips, accepts images from untrusted users, and runs an affected Active Storage\/libvips version. Rails 7.0.0 through 7.2.3.1, Rails 8.0.0 through 8.0.5, and Rails 8.1.0 through 8.1.3 are listed as branches that need upgrading. Rails 6.x is only relevant when the system has been configured to use Vips with Active Storage instead of the older default.<\/p>\n<p>The important point is that image variant generation does not need to be exposed as a separate endpoint. In many real applications, avatars, profile photos, product images, post images, or direct uploads that are reprocessed for display are enough for the image-processing chain to exist in normal business flows.<\/p>\n<h2>Why file read can lead to serious impact<\/h2>\n<p>Arbitrary file read is sometimes underestimated because it is not direct code execution. For modern web applications, that assumption is dangerous. Many operational secrets are stored in environment variables or configuration files: cookie-signing keys, credential decryption keys, database passwords, S3\/GCS\/Azure tokens, webhook secrets, payment API keys, or monitoring-system tokens.<\/p>\n<p>When these secrets are exposed, attackers can sign valid cookies, access file storage, read database content, spoof integration flows, or use the application privileges to expand into internal services. The patch is therefore only the first step; organizations should assume secrets may have been read if an affected application handled untrusted uploads.<\/p>\n<h2>How to reduce risk<\/h2>\n<p>Rails recommends upgrading to patched releases: Rails 7.2.3.2, 8.0.5.1, or 8.1.3.1, while ensuring libvips is version 8.13 or later. For environments that cannot upgrade Rails immediately, one temporary mitigation is to enable <strong>VIPS_BLOCK_UNTRUSTED<\/strong> if libvips is new enough, or call <strong>Vips.block_untrusted(true)<\/strong> when using ruby-vips 2.2.1 or later. If libvips is older than 8.13, Rails says there is no complete workaround other than upgrading or removing the libvips dependency from the application.<\/p>\n<p>After patching, operations teams should rotate <strong>secret_key_base<\/strong>, the master key, database credentials, image-storage service keys, and third-party tokens that the Rails process could read. Note that changing <strong>secret_key_base<\/strong> can invalidate cookies, login sessions, and signed URLs, so teams should prepare communication plans and an appropriate deployment window.<\/p>\n<h2>Lessons for development teams<\/h2>\n<p>CVE-2026-66066 reinforces a basic principle: image upload is not a low-risk feature. Image files can be complex inputs processed by many native libraries and format parsers. These libraries often have a broader attack surface than the upload form users see.<\/p>\n<p>For applications that allow user file uploads, development teams should separate image-processing privileges from secret-reading privileges, restrict worker filesystem access, control allowed formats, set size limits, scan input content, and monitor anomalies around upload endpoints. These measures do not replace the patch, but they reduce damage when a file-processing library has a new vulnerability.<\/p>\n<p>In the short term, Rails administrators should inventory applications using Active Storage, identify where Vips is used, update dependencies, rotate secrets, and monitor logs related to uploads or image variant processing. Internet-facing systems with public uploads should be treated as a high priority.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from The Hacker News, Ruby on Rails Security Advisory, and Ethiack<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>CVE-2026-66066 l\u00e0 l\u1ed7 h\u1ed5ng nghi\u00eam tr\u1ecdng trong Active Storage c\u1ee7a Ruby on Rails, li\u00ean quan \u0111\u1ebfn c\u00e1ch \u1ee9ng d\u1ee5ng x\u1eed l\u00fd \u1ea3nh t\u1ea3i l\u00ean b\u1eb1ng libvips. V\u1ea5n \u0111\u1ec1 \u0111\u00e1ng ch\u00fa \u00fd kh\u00f4ng n\u1eb1m \u1edf m\u1ed9t bi\u1ec3u m\u1eabu upload \u0111\u01a1n l\u1ebb, m\u00e0 \u1edf ranh gi\u1edbi tin c\u1eady gi\u1eefa t\u1ec7p do ng\u01b0\u1eddi d\u00f9ng g\u1eedi l\u00ean, b\u1ed9 x\u1eed [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1824,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[514,523,520,519,517,516,168,515,521,153,518,522],"class_list":["post-1826","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-kien-thuc","tag-cve-2026-66066","tag-ethiack","tag-image-upload-security","tag-kindarails2shell","tag-libvips","tag-rails-active-storage","tag-remote-code-execution","tag-ruby-on-rails","tag-secret_key_base","tag-the-hacker-news","tag-vips","tag-web-application-security"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=1826"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1826\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/1824"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=1826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=1826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=1826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}