CVE-2026-95098

Improper Neutralization of Special Elements used in an OS Command in the npm package pdf2image

Affected package: pdf2image (npm), 1.2.3 and all earlier versions.

Weakness: CWE-78: Improper Neutralization of Special Elements used in an OS Command.

Fixed version: none available. See Maintenance status below.

Usage at the time of reporting: around 1,760 downloads a week.

What the problem is

pdf2image converts a PDF to images by running the poppler and ImageMagick command line tools. Its readPDFInfo() and convertPDF() functions (index.js) place the PDF path directly into command strings that are run through a shell with child_process.exec. The path is trimmed of surrounding whitespace but never escaped or quoted, so shell syntax in the path is executed rather than treated as part of a filename.

Separately, the package evaluates its outputFormat option through Node's vm module. A project that allows a user to influence that option would be exposing code evaluation as well.

Impact

A project that passes a path or a piece of text that a user can influence into the affected call hands that user the ability to run commands as the account the Node process runs under. Typical exposure is a web application that accepts an upload and then processes the stored file.

How to fix it

Run the external binary without a shell and pass each value as its own argument, using child_process.execFile or child_process.spawn with an argument array. Every value is then treated as literal text rather than as part of a command line. Quoting the values inside the command string is not a reliable substitute.

Until a fixed release exists, projects depending on this package should either apply the change in a fork or move to a maintained alternative that does not build shell command strings from caller-supplied values.

Maintenance status

The latest release, 1.2.3, was published in July 2017. The project carries no security policy and no private reporting channel, so the report was made to MITRE as CNA of last resort. No fixed version is available.

Timeline

Credit and method

Reported by Brian Willows, Graith Internet. The finding and its analysis were AI-assisted, using Claude, and every claim was verified locally against the published package before the report was filed. The verification detail is held privately and is available to a maintainer or to a CVE numbering authority on request.

References

This advisory is published so that the CVE record has a public reference. Corrections are welcome at security@graith.co.uk.