<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ruby-on-Rails on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ruby-on-rails/</link><description>Recent content in Ruby-on-Rails on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 13:48:19 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ruby-on-rails/index.xml" rel="self" type="application/rss+xml"/><item><title>Rails patches critical Active Storage flaw with RCE potential</title><link>https://curasec.metacog.co.kr/insights/2026-08-03-rails-patches-critical-active-storage-flaw-with-rce-potentia/</link><pubDate>Mon, 03 Aug 2026 13:48:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-03-rails-patches-critical-active-storage-flaw-with-rce-potentia/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Active Storage is a core Rails component widely used for file handling, so any Rails-backed app is likely exposed; no public PoC or KEV listing yet, but the critical severity and unauthenticated file-read-to-RCE path make this a patch-this-sprint priority — update Rails to the fixed version.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>