RubyFlow The Ruby and Rails community linklog

×

The Ruby and Rails community linklog

Made a library? Written a blog post? Found a useful tutorial? Share it with the Ruby community here or just enjoy what everyone else has found!

Hot Cell for Active Storage

This summer, Mike handled CVE-2026-66066, an Active Storage vulnerability that let a crafted image upload read files from the server, including your application’s secrets.

His talk, Hot Cell: Securing Active Storage in the age of AI, was half post-mortem and half proposal: if we can’t stop image libraries from being vulnerable, maybe we can stop their vulnerabilities from reaching our secrets.

In this article, you will learn what that CVE actually meant, why patching image libraries is no longer enough, how Hot Cell sandboxes Active Storage, and whether you can use it in your Rails application today.

Rails World ‘26: Hot Cell for Active Storage

Post a comment

You can use basic HTML markup (e.g. <a>) or Markdown.

As you are not logged in, you will be
directed via GitHub to signup or sign in