Impact
A local OS command injection flaw exists in the image_optimizer Ruby gem version 1.3.0 through 1.9.0. The flaw is triggered by the ImageOptimizer#identify_format method when the identify option is enabled, allowing an attacker who controls the image path to supply shell metacharacters. The vulnerable code uses Ruby backticks, causing the embedded shell commands to execute with the privileges of the Ruby process, enabling arbitrary code execution.
Affected Systems
The vulnerability is limited to applications that depend on the jtescher image_optimizer gem within the specified version range. Systems that include the gem 1.3.0 to 1.9.0 in any Ruby application are at risk, regardless of platform, as long as they allow user supplied file names to reach the identify_format call.
Risk and Exploitability
The CVSS score of 9.3 classifies this as critical, indicating a high likelihood of exploitation if an attacker can influence the image path. An EPSS score of 2% indicates a low but nonzero probability of exploitation, suggesting that while the potential exists, attack frequency is expected to be modest. Because the vulnerability is not currently listed in the CISA KEV catalog, no active exploit signatures are known, yet the ability to execute shell commands on the application server remains extremely dangerous. The likely attack vector involves an attacker uploading a file with a specially crafted name that contains shell metacharacters; if the image is processed with the identify option, the backtick command string is executed by the Ruby interpreter.
OpenCVE Enrichment