Nodepdf Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 1
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2016-4991

    Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.

    Last Modified: Nov 21, 2024
    Published: Jul 28, 2022
    Items Per Page
    Nodepdf_Project Vulnerabilities & Security CVEs | CVE-DB