CRITICAL
jtescher
CVE published 2026-10-08
CVE-2026-107704
The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. This vulnerability can be exploited by attackers controlling the path, such as an uploaded file name, who can append shell metacharacters like ';' that are executed [truncated]