PT-2026-81173 · Npm · Node-Poppler

·

CVE-2026-78637

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions node-poppler versions 9.1.2 and 10.0.1
Description An argument injection flaw exists in the Argument Injection Handler component within the src/index.js file. A remote attacker can trigger this issue by manipulating the file path argument used in the following functions: pdfInfo(), pdfToText(), pdfToCairo(), pdfToPpm(), pdfImages(), pdfToHtml(), pdfToPs(), pdfFonts(), pdfDetach(), pdfAttach(), pdfSeparate(), and pdfUnite().
Recommendations Apply patch db6e3f79d3beb20601be7e59669c39811ae3c330 for version 9.1.2. Apply patch db6e3f79d3beb20601be7e59669c39811ae3c330 for version 10.0.1.

Exploit

Fix

Argument Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78637

Affected Products

Node-Poppler