CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107703

CRITICALCVSS 9.8NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_proc

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107703 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107703

CRITICALCVSS 9.8NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_proc

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]