CVE-2026-107703
EUVD-2026-9514808.10.2026, 19:17
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References