[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-rails-kr2s-was-i-vulnerable":3,"mdc--5e6chu-key":37,"related-repo-rails-kr2s-was-i-vulnerable":125,"related-org-rails-kr2s-was-i-vulnerable":149},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":11,"stars":27,"repoUrl":28,"updatedAt":29,"license":30,"forks":31,"topics":32,"repo":33,"sourceUrl":35,"mdContent":36},"kr2s-was-i-vulnerable","assess Rails application vulnerability to CVEs","Determine whether a Rails application was ever exposed to CVE-2026-66066, and\nif so produce the exposure window and the other facts a forensic sweep needs.\nRuns first; kr2s-was-i-exploited consumes its output.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},"rails","Ruby on Rails","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Frails.png",[12,16,19,22,24],{"name":13,"slug":14,"type":15},"Security","security","tag",{"name":17,"slug":18,"type":15},"Audit","audit",{"name":20,"slug":21,"type":15},"Code Analysis","code-analysis",{"name":9,"slug":23,"type":15},"ruby-on-rails",{"name":25,"slug":26,"type":15},"Risk Assessment","risk-assessment",15,"https:\u002F\u002Fgithub.com\u002Frails\u002Frails-forensics-CVE-2026-66066","2026-08-01T06:06:33.131688",null,1,[],{"repoUrl":28,"stars":27,"forks":31,"topics":34,"description":30},[],"https:\u002F\u002Fgithub.com\u002Frails\u002Frails-forensics-CVE-2026-66066\u002Ftree\u002FHEAD\u002Fskills\u002Fkr2s-was-i-vulnerable","---\nname: kr2s-was-i-vulnerable\ndescription: |\n  Determine whether a Rails application was ever exposed to CVE-2026-66066, and\n  if so produce the exposure window and the other facts a forensic sweep needs.\n  Runs first; kr2s-was-i-exploited consumes its output.\ntriggers:\n  - kr2s-was-i-vulnerable\n  - was i vulnerable\n  - were we vulnerable\n  - am i vulnerable\n  - are we affected by CVE-2026-66066\n  - CVE-2026-66066\n  - GHSA-xr9x-r78c-5hrm\n  - KindaRails2Shell\n  - is this app affected by the libvips rails vulnerability\n  - active storage libvips vulnerability\n  - matload vulnerability rails\n  - do we use vips variant processor\n  - exposure window for CVE-2026-66066\n  - when were we vulnerable\n---\n\n# kr2s-was-i-vulnerable\n\nOpen `@references\u002Fguide.md` and follow it. Do not proceed without it.\n\nDetermines whether a Rails application was ever exposed to CVE-2026-66066\n(GHSA-xr9x-r78c-5hrm), and produces the facts that `kr2s-was-i-exploited`\nrequires before it can sweep anything.\n\n**The deliverable is a window, not a yes or no.** For most applications reading\nthis today the present-tense answer is \"no, we patched.\" The useful answer is\nthe period during which the vulnerable code was serving production traffic,\nbecause that is what bounds the search for evidence.\n\nTwo things follow, and both are easy to get wrong.\n\nThe vulnerable code is gone from `HEAD`. Analyzing the current tree proves\nnothing. You have to check out the tree as it stood before the fix.\n\nThe window is bounded by deploy dates, not commit dates. Using the commit date\nfor the end of the window closes it before the fix was actually running, and\nsilently drops any attack in the gap.\n",{"data":38,"body":53},{"name":4,"description":6,"triggers":39},[4,40,41,42,43,44,45,46,47,48,49,50,51,52],"was i vulnerable","were we vulnerable","am i vulnerable","are we affected by CVE-2026-66066","CVE-2026-66066","GHSA-xr9x-r78c-5hrm","KindaRails2Shell","is this app affected by the libvips rails vulnerability","active storage libvips vulnerability","matload vulnerability rails","do we use vips variant processor","exposure window for CVE-2026-66066","when were we vulnerable",{"type":54,"children":55},"root",[56,63,78,91,102,107,120],{"type":57,"tag":58,"props":59,"children":60},"element","h1",{"id":4},[61],{"type":62,"value":4},"text",{"type":57,"tag":64,"props":65,"children":66},"p",{},[67,69,76],{"type":62,"value":68},"Open ",{"type":57,"tag":70,"props":71,"children":73},"code",{"className":72},[],[74],{"type":62,"value":75},"@references\u002Fguide.md",{"type":62,"value":77}," and follow it. Do not proceed without it.",{"type":57,"tag":64,"props":79,"children":80},{},[81,83,89],{"type":62,"value":82},"Determines whether a Rails application was ever exposed to CVE-2026-66066\n(GHSA-xr9x-r78c-5hrm), and produces the facts that ",{"type":57,"tag":70,"props":84,"children":86},{"className":85},[],[87],{"type":62,"value":88},"kr2s-was-i-exploited",{"type":62,"value":90},"\nrequires before it can sweep anything.",{"type":57,"tag":64,"props":92,"children":93},{},[94,100],{"type":57,"tag":95,"props":96,"children":97},"strong",{},[98],{"type":62,"value":99},"The deliverable is a window, not a yes or no.",{"type":62,"value":101}," For most applications reading\nthis today the present-tense answer is \"no, we patched.\" The useful answer is\nthe period during which the vulnerable code was serving production traffic,\nbecause that is what bounds the search for evidence.",{"type":57,"tag":64,"props":103,"children":104},{},[105],{"type":62,"value":106},"Two things follow, and both are easy to get wrong.",{"type":57,"tag":64,"props":108,"children":109},{},[110,112,118],{"type":62,"value":111},"The vulnerable code is gone from ",{"type":57,"tag":70,"props":113,"children":115},{"className":114},[],[116],{"type":62,"value":117},"HEAD",{"type":62,"value":119},". Analyzing the current tree proves\nnothing. You have to check out the tree as it stood before the fix.",{"type":57,"tag":64,"props":121,"children":122},{},[123],{"type":62,"value":124},"The window is bounded by deploy dates, not commit dates. Using the commit date\nfor the end of the window closes it before the fix was actually running, and\nsilently drops any attack in the gap.",{"items":126,"total":148},[127,140],{"slug":88,"name":88,"fn":128,"description":129,"org":130,"tags":131,"stars":27,"repoUrl":28,"updatedAt":139},"investigate Rails applications for CVE exploitation","Search a Rails application's Active Storage for evidence that CVE-2026-66066\nwas exploited against it, establish exactly what any crafted file read, and\ndecide whether that constitutes exfiltration. Requires an exposure window,\nwhich kr2s-was-i-vulnerable produces.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[132,133,134,137,138],{"name":17,"slug":18,"type":15},{"name":20,"slug":21,"type":15},{"name":135,"slug":136,"type":15},"Debugging","debugging",{"name":9,"slug":23,"type":15},{"name":13,"slug":14,"type":15},"2026-08-01T06:06:35.243268",{"slug":4,"name":4,"fn":5,"description":6,"org":141,"tags":142,"stars":27,"repoUrl":28,"updatedAt":29},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[143,144,145,146,147],{"name":17,"slug":18,"type":15},{"name":20,"slug":21,"type":15},{"name":25,"slug":26,"type":15},{"name":9,"slug":23,"type":15},{"name":13,"slug":14,"type":15},2,{"items":150,"total":148},[151,159],{"slug":88,"name":88,"fn":128,"description":129,"org":152,"tags":153,"stars":27,"repoUrl":28,"updatedAt":139},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[154,155,156,157,158],{"name":17,"slug":18,"type":15},{"name":20,"slug":21,"type":15},{"name":135,"slug":136,"type":15},{"name":9,"slug":23,"type":15},{"name":13,"slug":14,"type":15},{"slug":4,"name":4,"fn":5,"description":6,"org":160,"tags":161,"stars":27,"repoUrl":28,"updatedAt":29},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[162,163,164,165,166],{"name":17,"slug":18,"type":15},{"name":20,"slug":21,"type":15},{"name":25,"slug":26,"type":15},{"name":9,"slug":23,"type":15},{"name":13,"slug":14,"type":15}]