HIGH8.8
GHSA-8jh2-3mw6-6pfm
node-ts-ocr is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js
Details
NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/node-ts-ocr
No fixed version published yet for node-ts-ocr (npm). Pin to a known-safe version or switch to an alternative.