CVE-2026-70378: Theotherphil Imagecli
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width — a function that panics when given a width below 2, crashing the process.
Affected products
- Theotherphil Imagecli: up to and including 0.2.1
Published 2026-08-05. Last modified 2026-08-28.