Lucene search

K
osvGoogleOSV:GHSA-RV7P-MMWQ-X674
HistoryMay 10, 2021 - 6:46 p.m.

Improper Input Validation and Code Injection in pdf-image

2021-05-1018:46:58
Google
osv.dev
8
input validation
code injection
pdf-image
npm package
arbitrary code
untrusted user input

EPSS

0.006

Percentile

78.9%

Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.

EPSS

0.006

Percentile

78.9%

Related for OSV:GHSA-RV7P-MMWQ-X674