Description
ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: 1.5% Low
KEV: No
Impact: Arbitrary command execution
Action: Immediate Patch
AI Analysis

Impact

ppt2png through 0.0.6 allows attackers to inject operating system commands by supplying unsanitized input or output path arguments. By appending shell metacharacters such as ';' to file names that are later passed to child_process.exec() in the ppt2png.js source, an attacker can cause the Node.js process to execute arbitrary shell commands with the same privileges as the application. This flaw enables full remote code execution, allowing manipulation of files, data exfiltration, or deployment of additional malware.

Affected Systems

The vulnerability exists in the tzwm:ppt2png package, affecting all released versions up to and including 0.0.6. Users who incorporate this library into their applications or run the command line tool are susceptible.

Risk and Exploitability

The flaw has a CVSS score of 9.3, indicating critical severity. The EPSS score is 1%, reflecting a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the injection by providing crafted path parameters; the attack vector is inferred to be local or remote depending on how ppt2png is exposed, but the impact remains the same—full command execution within the Node.js environment.

Generated by OpenCVE AI on October 9, 2026 at 14:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched or newer version of ppt2png if available, or replace the library with a safer alternative.
  • Validate or sanitize any user‑supplied input for file names, rejecting paths containing shell metacharacters or normalizing them before passing to exec.
  • Replace child_process.exec() calls with child_process.spawn() or execFile(), providing arguments as separate parameters to avoid shell interpretation.

Generated by OpenCVE AI on October 9, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Tzwm
Tzwm ppt2png
Vendors & Products Tzwm
Tzwm ppt2png

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.
Title ppt2png through 0.0.6 OS Command Injection via input and output paths
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T18:36:35.066Z

Reserved: 2026-10-08T16:52:24.549Z

Link: CVE-2026-107699

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T19:17:01.853

Modified: 2026-10-08T21:35:53.890

Link: CVE-2026-107699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T14:45:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')