Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are , >= 8.0, , and >= 8.1, . Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults.