Description
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
Remediation
References
https://hackerone.com/reports/781664
Related Vulnerabilities
CVE-2021-23797 Vulnerability in npm package http-server-node
CVE-2019-10349 Vulnerability in maven package org.jenkins-ci.plugins:depgraph-view
CVE-2023-22578 Vulnerability in npm package sequelize
CVE-2021-27290 Vulnerability in maven package org.webjars.npm:ssri
CVE-2022-36100 Vulnerability in maven package org.xwiki.platform:xwiki-platform-tag-ui