CVE-2026-107704 PUBLISHED

image_optimizer 1.3.0 through 1.9.0 OS Command Injection via identify_format

Assigner: VulnCheck
Reserved: 08.10.2026 Published: 08.10.2026 Updated: 09.10.2026

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby process privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor jtescher
Product image_optimizer
Versions Default: unaffected
  • affected from 1.3.0 to 1.9.0 (incl.)

Credits

  • William Pierson (Retro16) finder

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE