Hackers are exploiting a critical vulnerability in Ruby on Rails that leads to remote code execution (RCE), VulnCheck warns.
Tracked as CVE-2026-66066 (CVSS score of 9.5) and referred to as KindaRails2Shell, the flaw is described as an arbitrary file read that leads to covert exposure, RCE, and lateral movement.
The security flaw was disclosed in late July when Ruby on Rails released patches for it, demanding an immediate fix for all Rails applications that rely on libvips to process Active Storage images and allow image uploads by untrusted users.
Shortly thereafter, security researchers reverse-engineered the bug and released technical information and proof-of-concept (PoC) code targeting it and Rails published forensic tools to help detect exploitation attempts.
Rails explain that KindaRails2Shell is rooted in the various methods used by various libraries and functions to read arbitrary files.
While Rails can rely on the client-supplied content type to interpret a blob as an image, libvips looks at the magic bytes to determine the file type.
This allows an attacker to create a file and declare it as MATLAB level 5, which causes the libvips MATLAB loader to be selected. The file is then directed to libmatio, which identifies MAT 7.3 in a header field and passes it to HDF5.
“HDF5’s external file list allows the bytes of a dataset to live in another file named by path and offset, so rendering the ‘image’ reads the attacker’s chosen file off-server and returns its contents as pixels. The same confusion, twice, on two layers that can’t see each other’s fields,” notes Rails.
An unauthorized attacker can target anything a Rails process can read, including the credential database and storage keys. Armed with the compromised secrets, the attacker can then spoof sessions, gain access to additional systems, and execute arbitrary code remotely.
According to VulnCheck, the actors involved in the threat began to exploit CVE-2026-66066 last week, roughly a month after the patches were released.
Additionally, VulnCheck says that his tests on a server with patch 8.1.3.1 reveal that “while the patch blocks reading of the libvips file, it does not neutralize the deserialization of the Marshal: RCE plugin variation key still runs on a patched server where a valid signature is given.”
In early August, VulnCheck identified about 7,000 open Ruby on Rails instances vulnerable to KindaRails2Shell.
Related: More details on exploited PaperCut vulnerabilities emerge
Related: OpenAI agents exploited a bug in the Linux kernel on the company’s own systems
Related: Recent Citrix NetScaler Vulnerability Exploited in the Wild
Related: Adobe and Nvidia patch dozens of vulnerabilities