CVE-2026-26830Disclosure(pdf-image_project / pdf-image)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch pdf-image_project pdf-image systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process.exec()

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdf-image

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
pdf-image

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-26: 2Mentions · 2026-03-28: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-28: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 1Technical Details · 2026-03-28: 103-2503-2603-28
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure2
2026-03-262
Disclosure2
2026-03-281
Disclosure1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `pdf-image` contains a CRITICAL OS Command Injection vulnerability (CVE-2026-26830) via `pdfFilePath`, enabling arbitrary command execution. Strong input validation is advised. #infosec #OSCommandInjection https://www.pulsepatch.io/posts/cve-2026-26830-pdf-image-os-command-injection

    Post summary

    The tweet announces a critical OS Command Injection (CVE‑2026‑26830) in pdf‑image, notes the vulnerability via `pdfFilePath` allows arbitrary command execution, urges strong input validation, and links to a Pulsepatch post for details.

    0000025
    6 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-26830 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-26830 #CVE-2026-26830 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/8ATKkgELUZ

    Post summary

    A new critical vulnerability (CVE‑2026‑26830) has been announced with a CVSS score of 9.8, but no further technical details or mitigation steps are provided.

    0000039
    114 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26830 - Critical pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.... https://www.thehackerwire.com/vulnerability/CVE-2026-26830/ https://t.co/238yApN8qH

    Post summary

    The tweet announces a critical OS command injection flaw in the pdf‑image npm package (up to v2.0.0) with technical details provided, but no PoC, exploit code, active use, patch, or false‑positive claim.

    0000056
    148 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26830: CRITICAL] Critical OS command injection vulnerability identified in pdf-image npm package v2.0.0 via pdfFilePath parameter. Utilizing user-controlled file paths leads to potential exploit.#cve,CVE-2026-26830,#cybersecurity https://cvefind.com/CVE-2026-26830

    Post summary

    The post announces a critical OS command injection flaw in the pdf-image npm package v2.0.0, detailing the vulnerable pdfFilePath parameter, without mentioning patches, PoC, or active exploitation.

    0000045
    605 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26830: n/a (CVSS... Shell injection through util.format() in pdf-image npm package - trivial RCE via filename manipulation, zero auth required. #RCE #npm #nodejs. https://zerodaysignal.com/vulnerability/CVE-2026-26830 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discloses CVE-2026-26830, highlighting a shell injection in the pdf‑image npm package that allows arbitrary RCE without authentication, and provides a link for further details.

    0000087
    168 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppdf-image_projectpdf-image-node.js-

Explore more