CVE-2026-66066: What Rails Active Storage Users Need to Know A breakdown of CVE-2026-66066, an arbitrary file read flaw in Rails Active Storage that can escalate to remote code execution, plus the libvips dependency you must update alongside it.