35 comments

[ 0.19 ms ] story [ 17.2 ms ] thread
i thought cloudflare would protect against those no?
Since the vulnerability is exploited by a crafted binary file, I think that isn't something that CF's managed ruleset is able to protect against. They have the ability to scan incoming files with antivirus, but if the exploit is small and simple and can be mutated per request, I think it's unlikely any AV would pick it up.
I agree. And unstated in this write up is the direct upload route. Even if your Cloudflare was perfect, once the attacker got the preflight they send the binary file up to S3 directly and then hit the variant route directly. The first code to “validate” the upload was the exploitable libvips code.
Do you have to have matlab running on your rails server for this to happen?
Not running, but supported. You can check your app with:

    bin/rails runner '
      require "vips"
      puts "ruby-vips #{Vips::VERSION}  libvips #{Vips.version(0)}.#{Vips.version(1)}.#{Vips.version(2)}"
      begin
        Vips::Operation.new("matload")
        puts "matload PRESENT - this build can reach libmatio"
      rescue Vips::Error
        puts "matload ABSENT - this build cannot reach libmatio"
      end
    '
This is from the Rails official docs for the CVE which they released as an agent skill. https://github.com/rails/rails-forensics-CVE-2026-66066/blob...
Why would you have matlab on an external server? People don't even have a compiler on the server in this situation. Crazy.
An agent skill is the official distribution format for the forensics on a 9.5. I mean, I get it, anyone running a Rails app right now is pasting "am I affected" into an agent anyway, but it's the kind of thing that would've sounded like a joke a couple years ago.
Makes sense though. Agent skills are - by a mix of LLM nature and fashion - just high-quality documentation. Documentation that only gets written now, because agents are what makes docs "something immediately and directly useful for me right now", vs. "something I should write so others may benefit, someday, somehow".

Human incentives are funny.

DHH needs to focus on Rails again rather than Omarchy.
(comment deleted)
He’s still very supportive of Rails. Come join us at RailsWorld in Austin later this month and see for yourself!
I don't know. Austin isn't the city I fell in love with in the 90s and early 2000s. Chiefly because it's no longer full of native Texans.
Took me a minute, but absolutely lovely.
I’m a native Texan, and I can deign to go to Austin for a couple days even though I live in a much bigger city in Texas which has delicious food from far more countries than Austin does. Plenty of Texans, and plenty of room for people from everywhere.
This post could be 10% as long:

- There was a bug with a patch

- We applied it to our clients

- There were live exploits within eight hours of the patch being released

- The Rails team had to expedite release of the technical details because POCs obviated the need to embargo

What is shocking to me is that it took eight hours.
> In practice, that embargo was functionally meaningless from the moment the patch shipped, and not because anyone breached it. The fix itself, a public code diff, was never embargoed at all, only the explanation of how to exploit it. That explanation didn’t even hold for a month.

Yeah, even if you embargo the patch there’s a high chance it won’t help either these days. See recently discussed Just the rumour of a bug is enough to find an exploit these days https://news.ycombinator.com/item?id=49480466

Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people.

We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.

What a time to be alive.

The fix is pretty easy -- you should call `block_untrusted` to stop loaders like matlab from running:

https://www.rubydoc.info/gems/ruby-vips/Vips.block_untrusted

You can also set the env var `VIPS_BLOCK_UNTRUSTED`, which might be easier.

You can block or allow specific load operations, so you can limit format support to just the types you need:

https://www.rubydoc.info/gems/ruby-vips/Vips#block-class_met...

That might be even better.

There was a post on libvips.org about this a while ago:

https://www.libvips.org/2022/05/28/What's-new-in-8.13.html

And a note about it in the checklist for devs:

https://www.libvips.org/API/current/developer-checklist.html...

I wanted to say I really, really appreciate your comment here John. libvips is a very useful tool set and maintaining it is certainly a bigger public challenge than I ever took on. I just wish the Ruby on Rails community had hardened their use of it sooner. Again, thank you.
> That is about as bad as it gets and meant that any delay in patching was an existential risk of imminent compromise.

Overdramatized.

It means compromise if you delay patching and don't take the unpatched deployment offline.

Oh right, this is government sites; every second of down time is lost revenue.

This website is format is really weird for mobile, I can only read two lines of text. The rest is covered by a big banner. Im on IOS. Anybody else having this issue or is it just me?
Thanks for the heads up. The navigation header does not collapse as I never liked hamburger menus but it should be more than two lines. Works more than that on my iPhone 16. What size is yours? I will pull it up in the Firefox simulator next week and try to make it better.

We recently updated the design. This is a very old site so it has some quirks in the design for sure.

Android Firefox here, top nav takes up 1/3rd of the viewport
Same. So much spacing between the 3 lines. If they want to keep that huge header I'd suggest it gracefully entirely disappear when scrolling down and reappear when scrolling up.
Thank you. I will work on that.
I didn't go with the scroll up but did drastically shrink the header and make a hamburger menu. I still like having it sticky because many a time I have been on a page and forgot who I was reading. Hopefully what is up now is a good tradeoff and provides good experience for a future reader.

Appreciate you.

You’re welcome. The banner obscures the view almost totally and I can read only 2 lines of text and scroll through that. I have a small device, Iphone se2022 if it helps.
Same thing in Firefox on Android but I used uBO element picker to select the header and nuke it. There is a link to the home page on the HTML below it and links in the footer. There is little to gain from that sticky header and much to lose.
HN has moved on, but I wanted to come back again and say thank you to you and those who replied below. I just pushed an update to the website that makes the header much more mobile device friendly.
There are so many CVEs related to upload… and basic user/group/file permissions and proper rules within the web proxy could mitigate them.

It reeks of people just writing stuff and tossing it up thinking that they’ve crafted something so great they needn’t worry. Get a good platform team.