PulsePatch.io@pulsepatchioDisclosure
The tweet announces a critical OS Command Injection (CVE‑2026‑26830) in pdf‑image, notes the vulnerability via `pdfFilePath` allows arbitrary command execution, urges strong input validation, and links to a Pulsepatch post for details.
CVEarity@CVEarityDisclosure
A new critical vulnerability (CVE‑2026‑26830) has been announced with a CVSS score of 9.8, but no further technical details or mitigation steps are provided.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces a critical OS command injection flaw in the pdf‑image npm package (up to v2.0.0) with technical details provided, but no PoC, exploit code, active use, patch, or false‑positive claim.
CVEFind.com@CveFindComDisclosure
The post announces a critical OS command injection flaw in the pdf-image npm package v2.0.0, detailing the vulnerable pdfFilePath parameter, without mentioning patches, PoC, or active exploitation.
0day Signal@0dayPublishingDisclosure
The tweet discloses CVE-2026-26830, highlighting a shell injection in the pdf‑image npm package that allows arbitrary RCE without authentication, and provides a link for further details.