Description
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
Remediation
References
https://hackerone.com/reports/781664
Related Vulnerabilities
CVE-2023-4771 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2023-25572 Vulnerability in maven package org.webjars.npm:react-admin
CVE-2019-1003030 Vulnerability in maven package org.jenkins-ci.plugins.workflow:workflow-cps
CVE-2023-34234 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:protobufjs