Critical Rails Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code
2026/07/30 gbhackers — Ruby on Rails の Active Storage コンポーネントに存在する、深刻な脆弱性 CVE-2026-66066 を悪用する未認証の攻撃者は、脆弱なアプリケーション・サーバ上の任意ファイルを読み取り、リモートコード実行を引き起こす恐れがある。画像操作に libvips を使用するよう設定された、Rails アプリケーションにおける Active Storage のバリアント処理に、この脆弱性は影響を及ぼす。
Continue reading “Rails の深刻な脆弱性 CVE-2026-66066 が FIX:任意のファイル読み取りと RCE の恐れ”
You must be logged in to post a comment.