{
 "description": "Evidence-bound MITRE ATT&CK techniques observed in ctipilot.ch entries referencing Ruby on Rails Active Storage variant processing on libvips \u2014 unauthenticated arbitrary file read (and possible RCE via exposed application secrets) from an untrusted image upload; CVSS 4.0 9.5 assigned by GitHub Security Advisories as the Rails CNA; fixed in activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 and requires libvips >= 8.13 to be effective. Score = number of published entries mapping the technique. Pinned dataset: ATT&CK v19.1.",
 "domain": "enterprise-attack",
 "gradient": {
  "colors": [
   "#ffe766",
   "#ff6666"
  ],
  "maxValue": 1,
  "minValue": 0
 },
 "hideDisabled": false,
 "layout": {
  "layout": "side",
  "showID": true,
  "showName": true
 },
 "legendItems": [],
 "metadata": [
  {
   "name": "source",
   "value": "ctipilot.ch"
  },
  {
   "name": "entity",
   "value": "CVE-2026-66066"
  },
  {
   "name": "attack_version",
   "value": "19.1"
  }
 ],
 "name": "Ruby on Rails Active Storage variant processing on libvips \u2014 unauthenticated arbitrary file read (and possible RCE via exposed application secrets) from an untrusted image upload; CVSS 4.0 9.5 assigned by GitHub Security Advisories as the Rails CNA; fixed in activestorage 7.2.3.2 / 8.0.5.1 / 8.1.3.1 and requires libvips >= 8.13 to be effective \u2014 ctipilot.ch coverage",
 "sorting": 3,
 "techniques": [
  {
   "comment": "entries: 2026-07-31/cve-2026-66066-rails-activestorage-libvips-file-read",
   "score": 1,
   "techniqueID": "T1005"
  },
  {
   "comment": "entries: 2026-07-31/cve-2026-66066-rails-activestorage-libvips-file-read",
   "score": 1,
   "techniqueID": "T1190"
  },
  {
   "comment": "entries: 2026-07-31/cve-2026-66066-rails-activestorage-libvips-file-read",
   "score": 1,
   "techniqueID": "T1552"
  }
 ],
 "versions": {
  "attack": "19",
  "layer": "4.5",
  "navigator": "5.1.0"
 }
}