Product
The image_optimizer Ruby gem, versions 1.3.0 through 1.9.0, is vulnerable to OS command injection via the ImageOptimizer#identify_format method when processing malicious, user-supplied image paths.