← Zurück zur CVE-Suche

CVE-2026-26831

textract

Beschreibung

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization

CVSS 9.8EPSS 2.421%Risiko 1.19
Quelle öffnen
Veröffentlicht
2026-03-25 16:16:21
Betroffene Versionen
<=2.5.0
Typ
Package
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H