VDB
Sign up
CRITICAL9.8

GHSA-9pcj-m5rr-p28g

textract is vulnerable to OS Command Injection

Details

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/textract
Introduced in: 0

No fixed version published yet for textract (npm). Pin to a known-safe version or switch to an alternative.

References