VDB
Sign up
—

PYSEC-2026-886

ocrodjvu is vulnerable to Arbitrary File Modification via symlink attack

Quick fix

PYSEC-2026-886 — ocrodjvu: upgrade to the fixed version with the command below.

pip install --upgrade 'ocrodjvu>=0.4.6-2'

Details

ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ocrodjvu
Introduced in: 0.4.6-1Fixed in: 0.4.6-2
Fixpip install --upgrade 'ocrodjvu>=0.4.6-2'

References