OS Command Injection Vulnerability in @enmaso/node-convert by Enmaso
CVE-2026-107703
9.3CRITICAL
What is CVE-2026-107703?
The @enmaso/node-convert library, up to version 1.0.0, suffers from an OS command injection vulnerability in its convert.js module. Attackers can exploit this weakness by injecting shell metacharacters or a single quote into the unsanitized filepath and convertTo arguments, which are then executed by the Node.js process. This can lead to unauthorized execution of operating system commands, compromising system security. Implementing proper input validation and sanitization is crucial to mitigate this risk.
Affected Version(s)
@enmaso/node-convert 0 <= 1.0.0
