Back

CRITICAL

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering

Published Jul 28, 2022

Description

Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 28, 2022
Updated Aug 6, 2024
Reserved May 24, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a