QID 982615

QID 982615: Nodejs (npm) Security Update for pdf-image (GHSA-rv7p-mmwq-x674)

Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-rv7p-mmwq-x674 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982615

    Software Advisories
    Advisory ID Software Component Link
    GHSA-rv7p-mmwq-x674 pdf-image URL Logo github.com/advisories/GHSA-rv7p-mmwq-x674