CVE-2026-26830
pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process.exec()
Vendor
Product
CWE
Yayın Tarihi
2026-03-25 15:16:38
Güncelleme
2026-04-02 20:13:29
Source Identifier
cve@mitre.org
KEV Date Added
-