Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: ruby-on-rails (2 articles)Clear

Attackers exploit critical Langflow and Rails flaws to harvest secrets

VulnCheck reported active exploitation of two critical flaws, one in the AI workflow builder Langflow and one in Ruby on Rails. The Langflow bug, CVE-2026-0768, scored 9.8, lets an attacker run arbitrary Python code as root through improper input validation. The Rails bug, CVE-2026-66066 and nicknamed KindaRails2Shell at 9.5, lets an unauthenticated attacker read arbitrary files by uploading a crafted image that exploits a mismatch between Active Storage and the libvips image library, leaking secrets like the Rails master key and cloud credentials and ultimately enabling code execution. Detections jumped from about 50 to 360 within a day, with attackers querying environment variables for OpenAI and AWS keys and probing SSH access.

Check
Patch Langflow and Ruby on Rails to fixed versions now, and rotate any secrets an attacker could have read, including the Rails master key, database passwords, cloud credentials, and API keys.
Affected
Internet-facing Langflow servers (CVE-2026-0768) and Rails apps using Active Storage with libvips (CVE-2026-66066); attackers can run code as root or read files leaking the master key, cloud credentials, and API tokens.
Fix
Update both immediately, rotate exposed secrets, restrict internet exposure of Langflow, review logs for environment-variable probing and image-upload abuse, and treat any exposed instance as potentially credential-compromised.

Critical Rails flaw turns an image upload into a read of server secrets

The Ruby on Rails team disclosed a critical flaw in Active Storage that lets an unauthenticated attacker read arbitrary files by uploading a crafted image. Tracked as CVE-2026-66066 and scored 9.5, it affects applications that use the libvips image library and accept image uploads from untrusted users, which is the default in modern Rails. Active Storage passes uploads to libvips without disabling its unsafe image loaders, so a malicious file can read the server process environment, exposing the secret key base, database passwords, cloud storage keys, and API tokens. Those secrets can enable code execution and lateral movement. Rails is not aware of exploitation, and full details are held until August 28.

Check
Determine which Rails apps use Active Storage with libvips and accept untrusted image uploads, upgrade to the fixed releases, and ensure libvips is version 8.13 or newer.
Affected
Rails 7.0 through 8.1 applications using libvips Active Storage with untrusted image uploads (CVE-2026-66066); an unauthenticated upload can read server secrets, opening the door to code execution.
Fix
Upgrade Rails, update libvips to 8.13 or later, and rotate every secret the app can read, including the secret key base, master key, storage and database credentials, and third-party tokens.