Description
The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby process privileges.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: 1.7% Low
KEV: No
Impact: Operating System Command Execution
Action: Patch Immediately
AI Analysis

Impact

A local OS command injection flaw exists in the image_optimizer Ruby gem version 1.3.0 through 1.9.0. The flaw is triggered by the ImageOptimizer#identify_format method when the identify option is enabled, allowing an attacker who controls the image path to supply shell metacharacters. The vulnerable code uses Ruby backticks, causing the embedded shell commands to execute with the privileges of the Ruby process, enabling arbitrary code execution.

Affected Systems

The vulnerability is limited to applications that depend on the jtescher image_optimizer gem within the specified version range. Systems that include the gem 1.3.0 to 1.9.0 in any Ruby application are at risk, regardless of platform, as long as they allow user supplied file names to reach the identify_format call.

Risk and Exploitability

The CVSS score of 9.3 classifies this as critical, indicating a high likelihood of exploitation if an attacker can influence the image path. An EPSS score of 2% indicates a low but nonzero probability of exploitation, suggesting that while the potential exists, attack frequency is expected to be modest. Because the vulnerability is not currently listed in the CISA KEV catalog, no active exploit signatures are known, yet the ability to execute shell commands on the application server remains extremely dangerous. The likely attack vector involves an attacker uploading a file with a specially crafted name that contains shell metacharacters; if the image is processed with the identify option, the backtick command string is executed by the Ruby interpreter.

Generated by OpenCVE AI on October 9, 2026 at 14:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest image_optimizer gem release that removes the vulnerable identify_format method.
  • If an upgrade is not possible, disable the identify option or refuse any file name that contains shell metacharacters.
  • Validate or sanitize the image file path before handing it to ImageOptimizer#identify_format, stripping or encoding any shell metacharacters to prevent command execution.

Generated by OpenCVE AI on October 9, 2026 at 14:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Jtescher
Jtescher image Optimizer
Vendors & Products Jtescher
Jtescher image Optimizer

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby process privileges.
Title image_optimizer 1.3.0 through 1.9.0 OS Command Injection via identify_format
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Jtescher Image Optimizer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-09T14:05:27.930Z

Reserved: 2026-10-08T16:52:24.549Z

Link: CVE-2026-107704

cve-icon Vulnrichment

Updated: 2026-10-09T14:04:49.044Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T19:17:02.897

Modified: 2026-10-09T15:17:08.667

Link: CVE-2026-107704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T14:45:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')