PT-2026-27800 · Extract · Textract

Zebbern

·

Published

2026-03-25

·

Updated

2026-04-01

·

CVE-2026-26831

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions textract versions through 2.5.0
Description The software is susceptible to an OS Command Injection issue through the file path parameter in multiple extractors. Processing files with malicious filenames allows the filePath to be directly passed to child process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js without sufficient sanitization. The vulnerable parameter is filePath. The vulnerable function is child process.exec().
Recommendations Versions prior to 2.5.1 should be updated.

Exploit

Fix

OS Command Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-26831
GHSA-9PCJ-M5RR-P28G

Affected Products

Textract