Impact
ppt2png through 0.0.6 allows attackers to inject operating system commands by supplying unsanitized input or output path arguments. By appending shell metacharacters such as ';' to file names that are later passed to child_process.exec() in the ppt2png.js source, an attacker can cause the Node.js process to execute arbitrary shell commands with the same privileges as the application. This flaw enables full remote code execution, allowing manipulation of files, data exfiltration, or deployment of additional malware.
Affected Systems
The vulnerability exists in the tzwm:ppt2png package, affecting all released versions up to and including 0.0.6. Users who incorporate this library into their applications or run the command line tool are susceptible.
Risk and Exploitability
The flaw has a CVSS score of 9.3, indicating critical severity. The EPSS score is 1%, reflecting a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the injection by providing crafted path parameters; the attack vector is inferred to be local or remote depending on how ppt2png is exposed, but the impact remains the same—full command execution within the Node.js environment.
OpenCVE Enrichment