PT-2026-27801 · Unknown · Node-Tesseract-Ocr

CVE-2026-26832

·

Publicado

2026-03-25

·

Atualizado

2026-03-29

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions node-tesseract-ocr versions through 2.2.1
Description The recognize() function in src/index.js is susceptible to OS Command Injection due to insufficient input sanitization. Specifically, the file path parameter is incorporated into a shell command string and executed using child process.exec() without adequate validation. This allows for potential remote code execution.
Recommendations Versions prior to 2.2.1 are affected.

Exploit

Correção

RCE

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04940
CVE-2026-26832
GHSA-8J44-735H-W4W2

Produtos afetados

Node-Tesseract-Ocr