The image_optimizer Ruby gem, versions 1.3.0 through 1.9.0, has a critical OS command injection flaw: when the identify option is on, an attacker who controls an image path can run shell commands.
What Is It
CVE-2026-107704 is an OS command injection vulnerability (CWE-78) in the ImageOptimizer#identify_format method of the image_optimizer Ruby gem. VulnCheck disclosed it, and NVD published it on October 8, 2026.
When the identify option is enabled, the gem builds a shell command from the supplied image path and runs it with Ruby backticks. An attacker who controls that path can add shell metacharacters such as ; to run their own commands. An uploaded file name is one example of a path an attacker might control. The commands run with the same privileges as the Ruby process.
Why It Matters
VulnCheck scores the flaw 9.8 (Critical) under CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 (Critical) under CVSS 4.0. Under those scores, it can be exploited over the network with low complexity, with no privileges and no user interaction. A successful attack fully compromises confidentiality, integrity, and availability.
Apps that pass user-supplied file names to image_optimizer with identify enabled are directly exposed. Upload pipelines are the main example.
CVE-2026-107704 is not currently in CISA's Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation. The NVD record lists the CVE as "Deferred".
What's Vulnerable
- Package: image_optimizer (RubyGems,
pkg:gem/image_optimizer) - Vendor/Maintainer: jtescher
- Affected versions: 1.3.0 through 1.9.0 (inclusive)
- Vulnerable code path:
ImageOptimizer#identify_formatwhen the identify option is enabled
The NVD record points to the relevant code in lib/image_optimizer.rb (lines 37–47) and lib/image_optimizer/shell.rb (lines 30–32) at tag v1.9.0.
Patch Status
The source records do not name a fixed version, and there is no CISA required action because the CVE is not in KEV. Teams using image_optimizer should:
- Check whether any application runs versions 1.3.0–1.9.0.
- Check whether the identify option is enabled.
- Check whether image paths or file names can come from untrusted input.
- Watch the project repository and VulnCheck advisory for a fixed release.