📝
article
rubyweekly.com
·
July 30, 2026
You need to upgrade Rails 7.x and 8.x now
#811 — July 30, 2026 Read on the Web Ruby Weekly A Critical Active Storage Vulnerability in Rails — A specially crafted 'image' uploaded to Rails 7.x or 8.x apps in their default configuration can potentially expose arbitrary files on the server via Active Storage's vips processor. Patched in Rails 7.2.3.2, 8.0.5.1 and 8.1.3.1 . You may also need to upgrade libvips . Rails 6.x isn't affected by default . Rafael França and Rails Core 💡 The team that discovered the vulnerability has dubbe...
Read on rubyweekly.com →