CVE-2026-70377: Theotherphil Imagecli
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.
Affected products
- Theotherphil Imagecli: up to and including 0.2.1
Published 2026-08-05. Last modified 2026-08-28.