Government Rails Site Hit Hours After CVE Patch(rietta.com) |
Government Rails Site Hit Hours After CVE Patch(rietta.com) |
We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.
What a time to be alive.
https://www.rubydoc.info/gems/ruby-vips/Vips.block_untrusted
You can also set the env var `VIPS_BLOCK_UNTRUSTED`, which might be easier.
You can block or allow specific load operations, so you can limit format support to just the types you need:
https://www.rubydoc.info/gems/ruby-vips/Vips#block-class_met...
That might be even better.
There was a post on libvips.org about this a while ago:
https://www.libvips.org/2022/05/28/What's-new-in-8.13.html
And a note about it in the checklist for devs:
https://www.libvips.org/API/current/developer-checklist.html...
- There was a bug with a patch
- We applied it to our clients
- There were live exploits within eight hours of the patch being released
- The Rails team had to expedite release of the technical details because POCs obviated the need to embargo
bin/rails runner '
require "vips"
puts "ruby-vips #{Vips::VERSION} libvips #{Vips.version(0)}.#{Vips.version(1)}.#{Vips.version(2)}"
begin
Vips::Operation.new("matload")
puts "matload PRESENT - this build can reach libmatio"
rescue Vips::Error
puts "matload ABSENT - this build cannot reach libmatio"
end
'
This is from the Rails official docs for the CVE which, interestingly, they only released as an agent skill. https://github.com/rails/rails-forensics-CVE-2026-66066/blob... vips -l
VipsForeignLoadMat (matload), load mat from file (.mat), priority=0, untrusted, is_a, get_flags, get_flags_filename, header, loadWe recently updated the design. This is a very old site so it has some quirks in the design for sure.
The rails developers are incredibly smart and capable. They patched the exploit. The problem is that it’s too easy to reverse engineer based on the patch. They can’t do anything about that.
DHH created Rails.
Overdramatized.
It means compromise if you delay patching and don't take the unpatched deployment offline.
Oh right, this is government sites; every second of down time is lost revenue.
Human incentives are funny.