Last week I posted about the KindaRails2Shell (CVE-2026-66066) @metasploit-r7.bsky.social module I put together. Here's a @rapid7.com technical analysis to go with it! 💜 www.rapid7.com/blog/post/ra...
Rapid7
Rapid7 analyzes KindaRails2Shell (CVE-2026-66066), a Ruby on Rails Active Storage vulnerability that can allow attackers to abuse libvips and crafted MAT/HDF5 uploads to read arbitrary files from the ...
rapid7.com