security1 distinct publisher
Rapid7 carries CVE-2026-66066 from a Rails upload to Kernel#spawn
Rapid7 reproduced the Active Storage arbitrary file read on five Rails versions, then walked it through leaked signing material into remote code execution. Any app on 7.0 defaults taking untrusted uploads is a patch-now case.
Publishers:rapid7.com
Reality
- Evidence74
- Adoption35
- Hype gap+8
- Incentives60