PT-2026-27800 · Extract · Textract

Zebbern

·

Publicado

2026-03-25

·

Atualizado

2026-04-01

·

CVE-2026-26831

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions textract versions through 2.5.0
Description The software is susceptible to an OS Command Injection issue through the file path parameter in multiple extractors. Processing files with malicious filenames allows the filePath to be directly passed to child process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js without sufficient sanitization. The vulnerable parameter is filePath. The vulnerable function is child process.exec().
Recommendations Versions prior to 2.5.1 should be updated.

Exploit

Correção

OS Command Injection

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26831
GHSA-9PCJ-M5RR-P28G

Produtos afetados

Textract