{"api_version":"1","generated_at":"2026-07-23T18:56:36+00:00","cve":"CVE-2016-4991","urls":{"html":"https://cve.report/CVE-2016-4991","api":"https://cve.report/api/cve/CVE-2016-4991.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-4991","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-4991"},"summary":{"title":"CVE-2016-4991","description":"Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2022-07-28 17:15:00","updated_at":"2022-08-04 11:49:00"},"problem_types":["CWE-77"],"metrics":[],"references":[{"url":"https://lf.lc/cve/cve-2016-4991/","name":"https://lf.lc/cve/cve-2016-4991/","refsource":"MISC","tags":[],"title":"CVE-2016-4991: Command injection in NodePDF | Anthony Weems","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-4991","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-4991","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"4991","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nodepdf_project","cpe5":"nodepdf","cpe6":"1.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2016-4991","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"nodepdf","version":{"version_data":[{"version_value":"nodepdf 1.3.0"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-77"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://lf.lc/cve/cve-2016-4991/","url":"https://lf.lc/cve/cve-2016-4991/"}]},"description":{"description_data":[{"lang":"eng","value":"Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0."}]}},"nvd":{"publishedDate":"2022-07-28 17:15:00","lastModifiedDate":"2022-08-04 11:49:00","problem_types":["CWE-77"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nodepdf_project:nodepdf:1.3.0:*:*:*:*:node.js:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"4991","Ordinal":"90935","Title":"CVE-2016-4991","CVE":"CVE-2016-4991","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"4991","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}