CVE-2026-107704
Deferred Deferred - Pending Action

OS Command Injection in image_optimizer Ruby Gem

Vulnerability report for CVE-2026-107704, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby process privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jtescher image_optimizer 1.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The image_optimizer Ruby gem versions 1.3.0 to 1.9.0 has an OS command injection flaw in the ImageOptimizer#identify_format method. When the identify option is enabled, attackers can execute arbitrary commands by providing a specially crafted image path. This is possible because user-controlled paths (like uploaded filenames) can include shell metacharacters such as semicolons, which are then executed via Ruby backticks with the privileges of the Ruby process.

Detection Guidance

Check if the image_optimizer gem version 1.3.0 through 1.9.0 is installed. Run: gem list image_optimizer. If installed, verify if the identify option is enabled in your application configuration.

Impact Analysis

If you use the vulnerable image_optimizer gem with the identify option enabled, attackers could execute arbitrary commands on your system. This could lead to full system compromise, data theft, or further network infiltration depending on the Ruby process privileges. Uploaded files with malicious filenames could trigger this attack.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using this gem may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Upgrade the image_optimizer gem to a version beyond 1.9.0. If upgrading is not possible, disable the identify option in your application configuration to prevent command execution via crafted image paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107704. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart