Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-107704 2026-10-08

CVE-2026-107704: OS Command Injection in image_optimizer Ruby Gem (CVSS 9.8)

"The image_optimizer Ruby gem, versions 1.3.0 through 1.9.0, has a critical OS command injection flaw: when the identify option is on, an attacker who controls an image path can run shell commands."

The image_optimizer Ruby gem, versions 1.3.0 through 1.9.0, has a critical OS command injection flaw: when the identify option is on, an attacker who controls an image path can run shell commands.

What Is It

CVE-2026-107704 is an OS command injection vulnerability (CWE-78) in the ImageOptimizer#identify_format method of the image_optimizer Ruby gem. VulnCheck disclosed it, and NVD published it on October 8, 2026.

When the identify option is enabled, the gem builds a shell command from the supplied image path and runs it with Ruby backticks. An attacker who controls that path can add shell metacharacters such as ; to run their own commands. An uploaded file name is one example of a path an attacker might control. The commands run with the same privileges as the Ruby process.

Why It Matters

VulnCheck scores the flaw 9.8 (Critical) under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 (Critical) under CVSS 4.0. Under those scores, it can be exploited over the network with low complexity, with no privileges and no user interaction. A successful attack fully compromises confidentiality, integrity, and availability.

Apps that pass user-supplied file names to image_optimizer with identify enabled are directly exposed. Upload pipelines are the main example.

CVE-2026-107704 is not currently in CISA's Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation. The NVD record lists the CVE as "Deferred".

What's Vulnerable

The NVD record points to the relevant code in lib/image_optimizer.rb (lines 37–47) and lib/image_optimizer/shell.rb (lines 30–32) at tag v1.9.0.

Patch Status

The source records do not name a fixed version, and there is no CISA required action because the CVE is not in KEV. Teams using image_optimizer should:

Sources