{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/image_optimizer-1.3.0---1.9.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:image_optimizer_project:image_optimizer:*:*:*:*:*:ruby:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-107704"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["image_optimizer (1.3.0 - 1.9.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe image_optimizer Ruby gem, specifically versions 1.3.0 through 1.9.0, contains an OS command injection vulnerability located within the ImageOptimizer#identify_format method. This flaw manifests when the gem is configured with the 'identify' option enabled. An attacker capable of influencing the image path parameter (such as through a user-controlled file upload form or filename input) can inject arbitrary shell metacharacters, including semicolons. These injected characters are subsequently processed by Ruby's backtick execution operator, allowing the commands to run with the same privileges as the underlying Ruby application process. This vulnerability presents a significant risk to any Ruby-based web application that utilizes this gem for image processing tasks, as it potentially grants unauthenticated remote attackers the ability to execute arbitrary code on the host server.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-107704 allows an unauthenticated attacker to execute arbitrary OS commands on the host server. Depending on the privileges of the Ruby application process, this could lead to full system compromise, data exfiltration, or the deployment of persistent malware. Organizations using vulnerable versions of the image_optimizer gem in public-facing applications are at high risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams include:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the image_optimizer Ruby gem to a version beyond 1.9.0 immediately to mitigate CVE-2026-107704.\u003c/li\u003e\n\u003cli\u003eReview all web application code paths that pass user-supplied input to the image_optimizer gem, particularly focusing on file upload features.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and sanitization for any filenames or paths passed to backend image processing utilities to prevent shell metacharacter injection.\u003c/li\u003e\n\u003cli\u003eDeploy runtime application self-protection (RASP) or static analysis tools to monitor for suspicious command execution originating from the application layer.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:40:01Z","date_published":"2026-10-08T19:40:01Z","id":"https://feed.craftedsignal.io/briefs/2026-10-image-optimizer-rce/","summary":"The image_optimizer Ruby gem, versions 1.3.0 through 1.9.0, is vulnerable to OS command injection via the ImageOptimizer#identify_format method when processing malicious, user-supplied image paths.","title":"OS Command Injection in image_optimizer Ruby Gem","url":"https://feed.craftedsignal.io/briefs/2026-10-image-optimizer-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Image_optimizer (1.3.0 - 1.9.0)","version":"https://jsonfeed.org/version/1.1"}