zebbernCVE/CVE-2026-26831

zebbernCVE/CVE-2026-26831

Releases0
Advisory for textract ⌯⌲ 15 000 weekly downloads

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization