Back

HIGH

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js

Published May 7, 2026

Description

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 7, 2026
Updated May 8, 2026
Reserved Oct 27, 2025
CISA Vulnrichment
Updated May 8, 2026
NVD
Status Awaiting Analysis
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-8JH2-3MW6-6PFM