Pdf-image Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    3
    Critical Level Threats
    0
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-26830

    pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process.exec()

    Last Modified: Jun 18, 2026
    Published: Mar 25, 2026

    CVE-2020-8132

    Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.

    Last Modified: Nov 21, 2024
    Published: Feb 28, 2020

    CVE-2018-3757

    Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.

    Last Modified: Nov 21, 2024
    Published: Jun 01, 2018
    Items Per Page
    Pdf-Image_Project Vulnerabilities & Security CVEs | CVE-DB