Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • > That is about as bad as it gets and meant that any delay in patching was an existential risk of imminent compromise.

    Overdramatized.

    It means compromise if you delay patching and don't take the unpatched deployment offline.

    Oh right, this is government sites; every second of down time is lost revenue.

  • DHH needs to focus on Rails again rather than Omarchy.
  • What does DHH have to do with this? Omarchy itself isn’t known for being secure; here is a root escalation from five days ago https://news.ycombinator.com/item?id=49499854

    The rails developers are incredibly smart and capable. They patched the exploit. The problem is that it’s too easy to reverse engineer based on the patch. They can’t do anything about that.

    by tyre
  • He’s still very supportive of Rails. Come join us at RailsWorld in Austin later this month and see for yourself!
  • i thought cloudflare would protect against those no?
  • Where does it say the site used Cloudflare?
  • Cloudflare or a WAF may or may not help. These can often catch and block specific bot traffic, but not every attack payload is delivered naively. It would be part of a defense in depth. Having the underlying vulnerability fixed is critically important. For those on AWS, WAF & Shield is also very useful but at the end of the day these let legitimate traffic through, such as legitimately uploading a file that only in its contents is malformed.
  • Since the vulnerability is exploited by a crafted binary file, I think that isn't something that CF's managed ruleset is able to protect against. They have the ability to scan incoming files with antivirus, but if the exploit is small and simple and can be mutated per request, I think it's unlikely any AV would pick it up.
  • This website is format is really weird for mobile, I can only read two lines of text. The rest is covered by a big banner. Im on IOS. Anybody else having this issue or is it just me?
  • Same thing in Firefox on Android but I used uBO element picker to select the header and nuke it. There is a link to the home page on the HTML below it and links in the footer. There is little to gain from that sticky header and much to lose.
  • Thanks for the heads up. The navigation header does not collapse as I never liked hamburger menus but it should be more than two lines. Works more than that on my iPhone 16. What size is yours? I will pull it up in the Firefox simulator next week and try to make it better.

    We recently updated the design. This is a very old site so it has some quirks in the design for sure.

  • There are so many CVEs related to upload… and basic user/group/file permissions and proper rules within the web proxy could mitigate them.

    It reeks of people just writing stuff and tossing it up thinking that they’ve crafted something so great they needn’t worry. Get a good platform team.

  • Do you have to have matlab running on your rails server for this to happen?
  • I am not sure, but my read on the original disclosure is no. libvips itself has a variant processor for matlab v5 files, which the exploit took advantage of.
  • I think the answer is no - this would affect any Rails app with default settings that uses ActiveStorage. The "Preconditions" recap at the bottom here has all the appropriate caveats: https://ethiack.com/info-hub/research/kindarails2shell-how-a...
  • Not running, but supported. You can check your app with:

        bin/rails runner '
          require "vips"
          puts "ruby-vips #{Vips::VERSION}  libvips #{Vips.version(0)}.#{Vips.version(1)}.#{Vips.version(2)}"
          begin
            Vips::Operation.new("matload")
            puts "matload PRESENT - this build can reach libmatio"
          rescue Vips::Error
            puts "matload ABSENT - this build cannot reach libmatio"
          end
        '
    
    This is from the Rails official docs for the CVE which, interestingly, they only released as an agent skill. https://github.com/rails/rails-forensics-CVE-2026-66066/blob...
  • Nice write up, Claude.
  • This post could be 10% as long:

    - There was a bug with a patch

    - We applied it to our clients

    - There were live exploits within eight hours of the patch being released

    - The Rails team had to expedite release of the technical details because POCs obviated the need to embargo

    by tyre
  • What is shocking to me is that it took eight hours.
  • Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people.

    We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.

    What a time to be alive.

  • The fix is pretty easy -- you should call `block_untrusted` to stop loaders like matlab from running:

    https://www.rubydoc.info/gems/ruby-vips/Vips.block_untrusted

    You can also set the env var `VIPS_BLOCK_UNTRUSTED`, which might be easier.

    You can block or allow specific load operations, so you can limit format support to just the types you need:

    https://www.rubydoc.info/gems/ruby-vips/Vips#block-class_met...

    That might be even better.

    There was a post on libvips.org about this a while ago:

    https://www.libvips.org/2022/05/28/What's-new-in-8.13.html

    And a note about it in the checklist for devs:

    https://www.libvips.org/API/current/developer-checklist.html...