CRITICAL9.8
GHSA-rv7p-mmwq-x674
Improper Input Validation and Code Injection in pdf-image
Details
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/pdf-image
Introduced in:
0No fixed version published yet for pdf-image (npm). Pin to a known-safe version or switch to an alternative.