OS Command Injection in ImageOptimizer Ruby Gem by Jtescher
CVE-2026-107704
9.3CRITICAL
What is CVE-2026-107704?
The ImageOptimizer Ruby gem versions 1.3.0 to 1.9.0 contains a vulnerability that allows an attacker to execute arbitrary commands through OS command injection. This issue arises in the 'identify_format' method when users provide a crafted image path while the identify option is enabled. By controlling this path, such as through uploaded filenames, attackers can append shell metacharacters that the Ruby process executes with its privileges. Mitigating this vulnerability requires validating user input and sanitizing paths to prevent unintended command execution.
Affected Version(s)
image_optimizer 1.3.0 <= 1.9.0
