Vendor
high
advisory
Remote Code Execution and Arbitrary File Read in Ruby on Rails Active Storage
1 CVE 1 IOCA vulnerability (CVE-2026-66066) in Ruby on Rails Active Storage allows unauthenticated attackers to achieve arbitrary file read and remote code execution during the variant processing phase.
PoC
Active Storage +10
1c
1i
updated
high
threat
Vulnerability in Ruby on Rails Allows Remote Indirect Code Injection (XSS)
1 TTP 1 IOCA cross-site scripting (XSS) vulnerability has been discovered in Ruby on Rails versions prior to 1.7.1, enabling a remote attacker to perform an indirect remote code injection, allowing malicious scripts to be executed in the client's browser.
exploited
Ruby on Rails < 1.7.1
xss
web-vulnerability
ruby-on-rails
cross-site-scripting
1t
1i
high
advisory
Rails Active Storage Path Traversal Vulnerability
2 rules 1 TTPA path traversal vulnerability (CVE-2026-33195) exists in Rails Active Storage's DiskService#path_for, potentially allowing attackers to read, write, or delete arbitrary files on the server by crafting blob keys with path traversal sequences, impacting applications that pass user input as blob keys.
Active Storage
rails
path traversal
cve-2026-33195
2r
1t