OS Command Injection in ImageOptimizer Ruby Gem by Jtescher
CVE-2026-107704

9.3CRITICAL

Key Information:

Vendor

Jtescher

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107704?

The ImageOptimizer Ruby gem versions 1.3.0 to 1.9.0 contains a vulnerability that allows an attacker to execute arbitrary commands through OS command injection. This issue arises in the 'identify_format' method when users provide a crafted image path while the identify option is enabled. By controlling this path, such as through uploaded filenames, attackers can append shell metacharacters that the Ruby process executes with its privileges. Mitigating this vulnerability requires validating user input and sanitizing paths to prevent unintended command execution.

Affected Version(s)

image_optimizer 1.3.0 <= 1.9.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

William Pierson (Retro16)
.