Official GHSA-xr9x-r78c-5hrm / CVE-2026-66066. Critical CVSS 9.5 (CVSS:4.0). Active Storage did not disable libvips “unfuzzed” operations. Unauthenticated attacker may read arbitrary files including process environment (secret_key_base). Affected: activestorage < 7.2.3.2; >=8.0 <8.0.5.1; >=8.1 <8.1.3.1. Patched: 7.2.3.2, 8.0.5.1, 8.1.3.1. Requires libvips >= 8.13. Workaround: VIPS_BLOCK_UNTRUSTED or Vips.block_untrusted(true). Rotate all secrets. Attack-chain details deferred to 2026-08-28. Credits Ethiack and GMO Flatt Security (KindaRails2Shell).