Skip to content
Threat Feed
critical advisory

OS Command Injection in image_optimizer Ruby Gem

The image_optimizer Ruby gem, versions 1.3.0 through 1.9.0, is vulnerable to OS command injection via the ImageOptimizer#identify_format method when processing malicious, user-supplied image paths.

CVE search metadata

CVE search record: CVE-2026-107704. Severity: critical. CVSS: 9.8. KEV: no. Product: image_optimizer (1.3.0 - 1.9.0). Brief: OS Command Injection in image_optimizer Ruby Gem. Brief link: https://feed.craftedsignal.io/briefs/2026-10-image-optimizer-rce/

The image_optimizer Ruby gem, specifically versions 1.3.0 through 1.9.0, contains an OS command injection vulnerability located within the ImageOptimizer#identify_format method. This flaw manifests when the gem is configured with the 'identify' option enabled. An attacker capable of influencing the image path parameter (such as through a user-controlled file upload form or filename input) can inject arbitrary shell metacharacters, including semicolons. These injected characters are subsequently processed by Ruby's backtick execution operator, allowing the commands to run with the same privileges as the underlying Ruby application process. This vulnerability presents a significant risk to any Ruby-based web application that utilizes this gem for image processing tasks, as it potentially grants unauthenticated remote attackers the ability to execute arbitrary code on the host server.

Impact

Successful exploitation of CVE-2026-107704 allows an unauthenticated attacker to execute arbitrary OS commands on the host server. Depending on the privileges of the Ruby application process, this could lead to full system compromise, data exfiltration, or the deployment of persistent malware. Organizations using vulnerable versions of the image_optimizer gem in public-facing applications are at high risk.

Recommendation

Prioritized actions for development and security teams include:

  • Upgrade the image_optimizer Ruby gem to a version beyond 1.9.0 immediately to mitigate CVE-2026-107704.
  • Review all web application code paths that pass user-supplied input to the image_optimizer gem, particularly focusing on file upload features.
  • Implement strict input validation and sanitization for any filenames or paths passed to backend image processing utilities to prevent shell metacharacter injection.
  • Deploy runtime application self-protection (RASP) or static analysis tools to monitor for suspicious command execution originating from the application layer.

Immediate actions

Upgrade image_optimizer to version > 1.9.0

IT Operations 24h

Mitigations

Sanitize user-provided input for filenames passed to the image_optimizer gem

immediate Application Security

CVE-2026-107704