Vulnerability Description
All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they can specify the input pdf file path.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nrhirani | Node-Qpdf | All versions |
Related Weaknesses (CWE)
References
- https://github.com/nrhirani/node-qpdf/issues/23ExploitIssue Tracking
- https://security.snyk.io/vuln/SNYK-JS-NODEQPDF-5747918ExploitThird Party Advisory
- https://github.com/nrhirani/node-qpdf/issues/23ExploitIssue Tracking
- https://security.snyk.io/vuln/SNYK-JS-NODEQPDF-5747918ExploitThird Party Advisory
FAQ
What is CVE-2023-26155?
CVE-2023-26155 is a vulnerability with a CVSS score of 7.3 (HIGH). All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive comm...
How severe is CVE-2023-26155?
CVE-2023-26155 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26155?
Check the references section above for vendor advisories and patch information. Affected products include: Nrhirani Node-Qpdf.