← Voltar à pesquisa de CVEs

CVE-2026-26831

textract

Descrição

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization

CVSS 9.8EPSS 2.421%Risco 1.19
Ver fonte
Publicação
2026-03-25 16:16:21
Versões afetadas
<=2.5.0
Tipo
Package
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H