PT-2026-20786 · Node.Js+1 · Node.Js+1
Tygo-Van-Den-Hurk
·
Published
2026-02-18
·
Updated
2026-03-02
·
CVE-2026-26974
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Slyde versions 0.0.4 and below
Description
Slyde is a program used to create animated presentations from XML. A remote code execution issue exists because Node.js automatically imports
**/*.plugin.{js,mjs} files, including those from node modules. This allows any malicious package containing a .plugin.js file to execute arbitrary code when installed or required. All projects utilizing this loading behavior are affected, particularly those installing packages from untrusted sources.Recommendations
Upgrade to version 0.0.5 or later.
Audit and restrict which packages are installed in
node modules.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node.Js
Slyde