CRITICAL9.8
GHSA-q5mh-72xg-628w
pdf-image has an OS Command Injection Vulnerability through its pdfFilePath parameter
Details
pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process.exec().
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/pdf-image
Introduced in:
0No fixed version published yet for pdf-image (npm). Pin to a known-safe version or switch to an alternative.