CVE-2026-107703: @enmaso/node-convert through 1.0.0 OS Command Injection via filepath and convertTo
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by childprocess.exec() to execute operating system commands with Node.js process privileges.
Affected Software
Event History
Frequently Asked Questions
Which applications are realistically exposed?
Applications using @enmaso/node-convert through version 1.0.0 are exposed when an attacker can influence the filepath or convertTo values supplied to the package. The vulnerable code incorporates those values into an ImageMagick command.
What does an attacker need to exploit this issue?
An attacker needs the ability to provide crafted filepath or convertTo input containing shell metacharacters or a single quote. Exploitation requires no authentication or user interaction.
What level of access can successful exploitation provide?
Injected commands run with the privileges of the Node.js process that invokes the vulnerable conversion code. This can affect confidentiality, integrity, and availability of the host or resources accessible to that process.