Ethiack Helps Remediate Critical Vulnerability That Exposed More Than 500,000 Websites

European cybersecurity firm Ethiack has disclosed a critical security vulnerability in Ruby on Rails, one of the most widely used open-source web application frameworks powering hundreds of thousands of websites and digital services worldwide.

Known as KindaRails2Shell, the remote code execution (RCE) vulnerability enables attackers to read sensitive files, execute malicious code, and potentially gain full control of affected servers.

First released more than two decades ago, Ruby on Rails serves as the foundation for an estimated 500,000 web applications, including many high-profile online platforms and enterprise services.

The vulnerability was identified by Ethiack researchers André Baptista, Bruno Mendes, and Rafael Castilho in the framework’s default image processing component. Impacting Ruby on Rails versions 7.x and 8.x, the flaw can be triggered whenever users upload images, including profile photos, avatars, and thumbnails.

Instead of immediately disclosing the technical details, Ethiack followed a responsible disclosure process by privately reporting the issue to the Ruby on Rails maintainers. The company subsequently collaborated with GMO Flatt Security, a Tokyo-based security firm that independently discovered the same vulnerability several days later. Together, they supported a coordinated global remediation effort, helping affected organizations validate and deploy the required security updates.

The official security advisory for CVE-2026-66066 is now available, assigning the vulnerability a CVSS severity score of 9.5. Ethiack has also released comprehensive technical details and a step-by-step remediation guide on its blog.

André Baptista, CTO at Ethiack, commented:

“This is a critical remote code execution vulnerability that leaves web applications exposed any time a user uploads an image. The risk is severe and demands immediate action.

“Ethiack combines a team of world-class human hackers and AI pentesting agents, who work together to help cyber defenders. When dealing with an emergency like this, we prioritise speed, agility and responsibility. We worked closely with the Ruby on Rails team to support a coordinated, global remediation effort and enable a responsible disclosure process.

“Critical patches have now been released, but affected organisations should note that simply updating the framework may not be enough. They may also need to update a separate third-party image processing library. Fixing this vulnerability requires a multi-stage remediation process, and many deployments could remain exposed even after applying the primary patch.

“For full details of the vulnerability and guide on how to put things right, check out our blog post here.”

Join our LinkedIn group Information Security Community!

No posts to display