Skip to content

Improper Input Validation and Code Injection in pdf-image

High severity GitHub Reviewed Published May 10, 2021 to the GitHub Advisory Database • Updated Feb 1, 2023

Package

npm pdf-image (npm)

Affected versions

<= 2.0.0

Patched versions

None

Description

Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.

References

Published by the National Vulnerability Database Feb 28, 2020
Reviewed Apr 20, 2021
Published to the GitHub Advisory Database May 10, 2021
Last updated Feb 1, 2023

Severity

High

EPSS score

0.619%
(79th percentile)

CVE ID

CVE-2020-8132

GHSA ID

GHSA-rv7p-mmwq-x674

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.