CVE-2026-26832 is a critical OS Command Injection vulnerability (CWE-78) affecting all versions through 2.2.1 of the node-tesseract-ocr npm package. This flaw allows unauthenticated attackers to execute arbitrary operating system commands by injecting malicious input into the recognize() function's file path parameter, which is unsafely passed to child_process.exec(). With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector, low attack complexity, and results in complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, the vulnerability has received limited community discussion on social media platforms.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.1CPE matchmatch criteria | cpe:2.3:a:zapolnoch:tesseract_ocr:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.