Skip to content

Comment on Government Rails Site Hit Hours After CVE Patchparent

Comments

Not running, but supported. You can check your app with:

    bin/rails runner '
      require "vips"
      puts "ruby-vips #{Vips::VERSION}  libvips #{Vips.version(0)}.#{Vips.version(1)}.#{Vips.version(2)}"
      begin
        Vips::Operation.new("matload")
        puts "matload PRESENT - this build can reach libmatio"
      rescue Vips::Error
        puts "matload ABSENT - this build cannot reach libmatio"
      end
    '
This is from the Rails official docs for the CVE which, interestingly, they only released as an agent skill. https://github.com/rails/rails-forensics-CVE-2026-66066/blob...

An agent skill is the official distribution format for the forensics on a 9.5. I mean, I get it, anyone running a Rails app right now is pasting "am I affected" into an agent anyway, but it's the kind of thing that would've sounded like a joke a couple years ago.

Makes sense though. Agent skills are - by a mix of LLM nature and fashion - just high-quality documentation. Documentation that only gets written now, because agents are what makes docs "something immediately and directly useful for me right now", vs. "something I should write so others may benefit, someday, somehow".

Human incentives are funny.

Why would you have matlab on an external server? People don't even have a compiler on the server in this situation. Crazy.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.