Skip to content

chore(deps): update rails to 8.1.3.1 for CVE-2026-66066 - #2763

Merged
mroderick merged 1 commit into
masterfrom
fix/activestorage-cve-2026-66066
Jul 29, 2026
Merged

chore(deps): update rails to 8.1.3.1 for CVE-2026-66066#2763
mroderick merged 1 commit into
masterfrom
fix/activestorage-cve-2026-66066

Conversation

@mroderick

Copy link
Copy Markdown
Collaborator

Description

Fixes CVE-2026-66066 in Active Storage variant processing.

Changes

  • Update rails constraint from ~> 8.1.2 to ~> 8.1.3
  • Pulls in activestorage 8.1.3.1 which patches the vulnerability

Verification

  • 1156 examples, 0 failures
  • RuboCop clean (359 files)

activestorage 8.1.2.1 has CVE-2026-66066: Possible arbitrary file read and RCE in Active Storage variant processing.

Update rails constraint from ~> 8.1.2 to ~> 8.1.3. Resolves GHSA-xr9x-r78c-5hrm.
@mroderick
mroderick marked this pull request as ready for review July 29, 2026 17:29
@mroderick
mroderick merged commit 29df46a into master Jul 29, 2026
10 checks passed
@mroderick
mroderick deleted the fix/activestorage-cve-2026-66066 branch July 29, 2026 17:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant