BT Haberler[verified]@BTHaberlerDisclosure
CVE‑2026‑66066 is a high‑severity RCE flaw in Rails Active Storage that allows attackers to read secret keys and, combined with CVE‑2025‑24293, execute code via crafted MAT files. A third‑party PoC demonstrates the full exploit chain, but no patch or active exploitation is reported.
NeoTeo.com[verified]@NeoteoComDisclosure
Ethiack reported that a MATLAB/HDF5 file handled by Rails Active Storage can read server secrets and lead to a remote code execution via CVE-2025-24293.
The Hacker News@TheHackersNewsPoC
A PoC using a crafted MATLAB/HDF5 file demonstrates that CVE‑2025‑24293 allows attackers to read Rails secrets and achieve RCE, though no active exploitation is reported.
Sam Stones(Hunter)👨💻@SamTechwestDisclosure
The tweet announces a new exploitation method for CVE-2025-24293 involving MATLAB/HDF5 uploads that can expose Rails secret keys and lead to remote code execution, but provides no evidence of active attacks, patches, or a PoC.
ROHIT@rynosecDisclosure
The tweet announces a new CVE (CVE-2025-24293) concerning a missing validation in Rails' Active Storage Vips Transformer and links to a HackerOne report without providing exploit code or patch details.
CVE@CVEnewGeneral
The text notes the CVE-2025-24293 concerning potentially unsafe image transformation methods in Active Storage but provides no further technical details, exploitation evidence, or mitigation information.
0day Signal@0dayPublishingDisclosure
The text discloses a high‑severity command injection vulnerability in Rails Active Storage, specifying its nature and CVSS score but lacking evidence of active exploitation or mitigation.