Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process.exec()
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
pdf-image 安全漏洞
Vulnerability Description
pdf-image是Masafumi Oyamada个人开发者的一个PDF转PNG图片的Node.js工具。 pdf-image 2.0.0及之前版本存在安全漏洞,该漏洞源于pdfFilePath参数未经验证,可能导致OS命令注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A