Description
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
Remediation
References
https://hackerone.com/reports/330957
Related Vulnerabilities
CVE-2016-10531 Vulnerability in maven package org.webjars.npm:marked
CVE-2021-23397 Vulnerability in npm package @ianwalter/merge
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-metadata-query-service-jdbc
CVE-2022-29172 Vulnerability in npm package auth0-lock
CVE-2018-20318 Vulnerability in maven package com.github.binarywang:weixin-java-common