Government Rails Site Hit Hours After CVE Patch

rietta 84 points 25 comments September 04, 2026
rietta.com · View on Hacker News

Discussion Highlights (8 comments)

dorianmariecom

i thought cloudflare would protect against those no?

comrade1234

Do you have to have matlab running on your rails server for this to happen?

shevy-java

DHH needs to focus on Rails again rather than Omarchy.

tyre

This post could be 10% as long: - There was a bug with a patch - We applied it to our clients - There were live exploits within eight hours of the patch being released - The Rails team had to expedite release of the technical details because POCs obviated the need to embargo

jeremyjh

Nice write up, Claude.

throwatdem12311

Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people. We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell. What a time to be alive.

kazinator

> That is about as bad as it gets and meant that any delay in patching was an existential risk of imminent compromise. Overdramatized. It means compromise if you delay patching and don't take the unpatched deployment offline. Oh right, this is government sites; every second of down time is lost revenue.

onemoresoop

This website is format is really weird for mobile, I can only read two lines of text. The rest is covered by a big banner. Im on IOS. Anybody else having this issue or is it just me?

Semantic search powered by Rivestack pgvector
5,564 stories · 50,257 chunks indexed