diff --git a/gems/activestorage/CVE-2026-66066.yml b/gems/activestorage/CVE-2026-66066.yml index 1ae34fb69f..4dbc34ad84 100644 --- a/gems/activestorage/CVE-2026-66066.yml +++ b/gems/activestorage/CVE-2026-66066.yml @@ -6,7 +6,7 @@ ghsa: xr9x-r78c-5hrm url: https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-66066 title: Possible arbitrary file read and remote code execution in Active Storage variant processing -date: 2027-07-29 +date: 2026-07-29 description: | ## Impact @@ -51,8 +51,8 @@ description: | from Ethiack, and RyotaK from GMO Flatt Security Inc.. cvss_v4: 9.5 patched_versions: - - "~> 7.2.3.1" - - "~> 8.0.5.1" + - "~> 7.2.3, >= 7.2.3.2" + - "~> 8.0.5, >= 8.0.5.1" - ">= 8.1.3.1" related: url: