Nice write up, Claude.
This post could be 10% as long:
- There was a bug with a patch
- We applied it to our clients
- There were live exploits within eight hours of the patch being released
- The Rails team had to expedite release of the technical details because POCs obviated the need to embargo
This website is format is really weird for mobile, I can only read two lines of text. The rest is covered by a big banner. Im on IOS. Anybody else having this issue or is it just me?
Do you have to have matlab running on your rails server for this to happen?
i thought cloudflare would protect against those no?
[dead]
DHH needs to focus on Rails again rather than Omarchy.
> That is about as bad as it gets and meant that any delay in patching was an existential risk of imminent compromise.
Overdramatized.
It means compromise if you delay patching and don't take the unpatched deployment offline.
Oh right, this is government sites; every second of down time is lost revenue.
Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people.
We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.
What a time to be alive.