[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#libvips

articleCRITICAL 9.5

Critical Vulnerability in Active Storage: Arbitrary File Read and Remote Code Execution

A critical vulnerability (CVE-2026-66066) has been discovered in Active Storage, a popular Ruby on Rails component, which allows unauthenticated attackers to read arbitrary files from the server and potentially achieve remote code execution. The vulnerability has a CVSS score of 9.5 and affects applications using libvips for image processing and allowing image uploads from untrusted users. Immediate mitigation steps include upgrading to a fixed version of Active Storage, updating libvips to version 8.13 or higher, and changing sensitive secrets.

Jul 31, 20261 source
articleHIGH 7.0

Inheritance of High-Severity Vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591

Multiple high-severity vulnerabilities have been discovered in the libvips dependency used by the sharp library. These vulnerabilities, with a CVSS score of 7, affect versions of sharp prior to 0.35.0. The vulnerabilities have been patched in sharp version 0.35.3, which includes libvips 8.18.3. Immediate upgrade is recommended to prevent potential exploitation.

Jul 22, 20261 source