Lewati ke konten utama
ThreatsThe Hacker News

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key

Ringkasan ini kami kurasi dari The Hacker News. Baca artikel lengkapnya di sumber aslinya.

Baca selengkapnya di The Hacker News