A critical vulnerability tracked as CVE-2026-66066 affects the Active Storage component in Ruby on Rails, enabling unauthenticated attackers to read arbitrary files from a server and potentially escalate to remote code execution. The flaw exists when Active Storage uses the libvips image processing library to generate thumbnails from user-uploaded images.