VDB
Sign up
CRITICAL9.8

GHSA-q5mh-72xg-628w

pdf-image has an OS Command Injection Vulnerability through its pdfFilePath parameter

Details

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process.exec().

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/pdf-image
Introduced in: 0

No fixed version published yet for pdf-image (npm). Pin to a known-safe version or switch to an alternative.

References