Argument Injection Vulnerability in Fdawgs Node-Poppler by Fdawgs
CVE-2026-78637
6.9MEDIUM
What is CVE-2026-78637?
A vulnerability in the Fdawgs Node-Poppler library allows for argument injection via crafted file path manipulations within certain functions, including pdfInfo and pdfToHtml. This could lead to unauthorized access and misuse, instigated remotely through malicious interaction. It is critical to apply the available patch (db6e3f79d3beb20601be7e59669c39811ae3c330) to mitigate this risk.
Affected Version(s)
node-poppler 9.1.0
node-poppler 9.1.1
node-poppler 9.1.2
