Pdf-image Project
Pdf-image Project Pdf-image: vulnerabilidades y CVE
Pdf-image Project Pdf-image tiene 3 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses1
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-26830 | Crítica (9.8) | 3.2% | — | 25 mar 2026 | pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate… |
| CVE-2020-8132 | Crítica (9.8) | 2.0% | — | 28 feb 2020 | Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input. |
| CVE-2018-3757 | Crítica (9.8) | 4.6% | — | 1 jun 2018 | Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.