Skip to content
The Nexus
DossierENTITY

Active Storage

Coverage of Active Storage in the Nexus archive.

Earliest in view: Jul 29 · 18:10 UTCMost recent: Aug 1 · 14:20 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 1 · 14:20 UTCBLEEPING COMPUTER
    Rails patches critical Active Storage flaw with RCE potential

    A critical vulnerability in the Active Storage framework allows unauthenticated attackers to read arbitrary files from a Rails application, potentially escalating to remote code execution (RCE). The flaw has been patched by Rails.

  • SECURITYJul 29 · 18:10 UTCTHE HACKER NEWS
    Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

    Ruby on Rails has patched a critical Active Storage vulnerability (CVE-2026-66066) that could allow unauthenticated attackers to read arbitrary files from application servers via crafted image uploads. The flaw, rated with a CVSS score of 9.5, risks exposing sensitive data such as secret_key_base, Rails master key, database passwords, and cloud storage credentials.