
CVE-2026-66066
KindaRails2Shell
Educational security research repository for CVE-2026-66066 ("KindaRails2Shell").
This repository is intended for security research, vulnerability analysis, detection, and defensive purposes only.
KindaRails2Shell (CVE-2026-66066) is a critical vulnerability affecting Ruby on Rails Active Storage deployments that process uploaded images using libvips.
Under vulnerable configurations, a specially crafted image may trigger unintended behavior during image processing, potentially leading to:
.
├── README.md
├── docs/
│ ├── analysis.md
│ ├── timeline.md
│ └── references.md
├── detection/
│ ├── yara/
│ ├── sigma/
│ └── iocs.txt
├── screenshots/
├── images/
└── LICENSE
| Component | Status |
|---|---|
| Ruby on Rails | Affected |
| Active Storage | Affected |
| libvips | Affected in vulnerable configurations |
Possible indicators include:
This repository is provided strictly for educational, research, detection, and defensive security purposes.
Do not use any information contained here against systems without explicit authorization.
If you find this repository useful:
⭐ Star the repository
🍴 Fork it
🛡 Share it with the cybersecurity community
Made with ❤️ by the cybersecurity community.