Vulnerabilities > Nodepdf Project

DATE CVE VULNERABILITY TITLE RISK
2022-07-28 CVE-2016-4991 Command Injection vulnerability in Nodepdf Project Nodepdf 1.3.0
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering.
network
low complexity
nodepdf-project CWE-77
critical
9.8