VDB
Sign up
CRITICAL9.8

GHSA-rv7p-mmwq-x674

Improper Input Validation and Code Injection in pdf-image

Details

Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/pdf-image
Introduced in: 0

No fixed version published yet for pdf-image (npm). Pin to a known-safe version or switch to an alternative.

References