โ† Back to all CVEs

CVE-2026-26831

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Mar 25, 2026
Vendor unknown

Description

textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization

References