PT-2026-38438 · Npm · Node-Ts-Ocr

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2025-63705

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions node-ts-ocr version 1.0.15
Description The NPM package contains a flaw allowing OS Command Injection, which occurs when an application executes arbitrary operating system commands due to insufficient input validation. This issue is located within the invokeImageOcr() function in the src/index.js file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the invokeImageOcr() function to minimize the risk of exploitation.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-63705
GHSA-8JH2-3MW6-6PFM

Affected Products

Node-Ts-Ocr