I was in the audience at Rails World 2026 when Mike Dalessio, a Rails Core team member who joined earlier this year, put up a slide that said “You are not worried enough (probably).”
He had good reasons to say it.
This summer, Mike handled CVE-2026-66066 , an Active Storage vulnerability that let a crafted image upload read files from the server, including your application’s secrets.
His talk, Hot Cell: Securing Active Storage in the age of AI , was half post-mortem and half proposal: if we can’t stop image libraries from being vulnerable, maybe we can stop their vulnerabilities from reaching our secrets.
In this article, you will learn what that CVE actually meant, why patching image libraries is no longer enough, how Hot Cell sandboxes Active Storage, and whether you can use it in your Rails application today.
Read more of Rails World '26: Hot Cell for Active Storage