CRITICAL9.8
GHSA-9pcj-m5rr-p28g
textract is vulnerable to OS Command Injection
Details
textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/textract
Introduced in:
0No fixed version published yet for textract (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-26831[ADVISORY]
- https://github.com/dbashford/textract[PACKAGE]
- https://github.com/dbashford/textract/blob/master/lib/extractors/doc.js[WEB]
- https://github.com/dbashford/textract/blob/master/lib/extractors/rtf.js[WEB]
- https://github.com/dbashford/textract/blob/master/lib/util.js[WEB]
- https://github.com/zebbernCVE/CVE-2026-26831[WEB]
- https://www.npmjs.com/package/textract[WEB]