Just sent this to my boss. Felt like tossing a grenade over a fence into a party of unsuspecting people.

We don’t use ActiveStorage but Claude was able create a similar exploit in own our app in the exact same way via our own file upload library in 3 minutes simply by point Opus 5 at our site and asking it if we were vulnerable to an attack similar to KindaRails2Shell.

What a time to be alive.