Npm · Node-Poppler · CVE-2026-78637
**Name of the Vulnerable Software and Affected Versions**
node-poppler versions 9.1.2 and 10.0.1
**Description**
An argument injection flaw exists in the Argument Injection Handler component within the `src/index.js` file. A remote attacker can trigger this issue by manipulating the `file path` argument used in the following functions: `pdfInfo()`, `pdfToText()`, `pdfToCairo()`, `pdfToPpm()`, `pdfImages()`, `pdfToHtml()`, `pdfToPs()`, `pdfFonts()`, `pdfDetach()`, `pdfAttach()`, `pdfSeparate()`, and `pdfUnite()`.
**Recommendations**
Apply patch db6e3f79d3beb20601be7e59669c39811ae3c330 for version 9.1.2.
Apply patch db6e3f79d3beb20601be7e59669c39811ae3c330 for version 10.0.1.