CVE-2026-78637 | Fdawgs node-poppler up to 9.1.2/10.0.1 Argument Injection src/index.js file_path argument injection (Issue 822)
A vulnerability was found in Fdawgs node-poppler up to 9.1.2/10.0.1. It has been rated as critical. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Performing a manipulation of the argument file_path results in argument injection.
This vulnerability was named CVE-2026-78637. The attack may be initiated remotely. There is no available exploit.
It is recommended to apply a patch to fix this issue.VulDB Recent EntriesRead More