Description
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
Remediation
References
https://github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83
https://hackerone.com/reports/340208
Related Vulnerabilities
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.enigma2
CVE-2021-4279 Vulnerability in maven package org.webjars.bower:fast-json-patch
CVE-2021-23364 Vulnerability in npm package browserslist
CVE-2023-25572 Vulnerability in npm package react-admin
CVE-2011-0533 Vulnerability in maven package org.apache.continuum:continuum-webapp