← Back

CVE-2026-26831

nvd nist
Published: Mar 25, 2026Modified: Mar 30, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization

Affected (1)

Products: Dbashford: Textract
1 product
Textract
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.5.0

Timeline

No history available yet.