Rails Active Storage 8.2 libvips 不安全图像加载漏洞
Security AdvisoryHighRuby on Rails
Affected:
- Active Storage 8.2
- libvips < 8.13
- ruby-vips < 2.2.1
Fixed in:
- Active Storage >= 8.2.1
- libvips >= 8.13
- ruby-vips >= 2.2.1
Referenced CVEs: CVE-2026-66066 · 9.5
文章内图片已隐藏以节省流量 · 升级 Pro 后可见图片及离线存档
本文由本平台从 github.com 自动抓取,经 LLM 流水线清洗、双语翻译。版权归原作者。查看原文。