VDB
Sign up
HIGH8.8

GHSA-8jh2-3mw6-6pfm

node-ts-ocr is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js

Details

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-ts-ocr

No fixed version published yet for node-ts-ocr (npm). Pin to a known-safe version or switch to an alternative.

References