The Rails security team published attack details and -- more importantly -- tools and agent skills to run a forensic investigation to help you determine if you were exploited. Be careful out there. discuss.rubyonrails.org/t/cve-2026-6...
[CVE-2026-66066] Attack details, and tools to perform a forensic investigation
Hello there, I’m writing as a member of the Rails security team about CVE-2026-66066. As mentioned in the advisory, GHSA-xr9x-r78c-5hrm, we held back details about the attack vector to allow applicat...
discuss.rubyonrails.org
Upgrade Rails immediately, kids, this is a big one. github.com/rails/rails/...