CVE-2026-26830 is a critical OS command injection vulnerability affecting the pdf-image npm package, versions up to 2.0.0, through its pdfFilePath parameter. Rated 9.8 CVSS (Critical), this flaw allows an unauthenticated attacker to execute arbitrary commands on the host system with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not currently on CISA's Known Exploited Vulnerabilities (KEV) catalog, community discussions indicate that public exploit code is available, warranting immediate patching for affected pdf_image_project and pdf_image instances.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0CPE matchmatch criteria | cpe:2.3:a:pdf-image_project:pdf-image:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.