Description
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: 1.8% Low
KEV: No
Impact: Remote Code Execution via OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

@enmaso/node-convert through 1.0.0 contains an OS command injection flaw in convert.js. Unsanitized values supplied for the filepath and convertTo parameters are passed directly into a child_process.exec call that builds an ImageMagick command. An attacker can inject shell metacharacters or quote characters to terminate the intended command and execute arbitrary operating‑system commands with the privileges of the Node.js process. This provides full code‑execution capability and thus poses a severe confidentiality, integrity, and availability threat.

Affected Systems

All releases of @enmaso/node-convert up to and including 1.0.0 are affected. The security advisory lists no specific sub‑versions, but any distribution of the package whose version is 1.0.0 or earlier must be considered vulnerable. Users who still deploy the library in any form should treat the entire library as impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 9.3 classifies this vulnerability as Critical. With an EPSS score of 2%, the empirical likelihood of exploitation is low but nonzero, indicating that while widespread attacks have not been observed, the vulnerability could still be targeted. The attack vector is inferred to be remote, because the parameters that trigger the injection are exposed through API inputs that can be provided by untrusted users. An attacker who can influence these inputs, for example via an HTTP endpoint or a file upload mechanism, can therefore trigger the arbitrary command execution.

Generated by OpenCVE AI on October 9, 2026 at 14:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @enmaso/node-convert to a version that contains the OS command injection fix. The repository’s latest releases after 1.0.0 should no longer include the vulnerable exec call. If the library has not yet been updated, seek an alternative implementation that does not rely on child_process.exec for ImageMagick processing.
  • When an upgrade is not immediately possible, validate or sanitize the filepath and convertTo values before they reach the exec call. Reject any input that contains shell metacharacters, quotes, or whitespace that could alter command boundaries. This mitigates the injection vector by ensuring only the intended arguments are supplied.
  • Replace the unsafe exec usage with a safer alternative such as child_process.execFile or a dedicated ImageMagick binding that does not invoke a shell. If a stricter approach is required, restrict the set of allowed convertTo operations to a whitelist of known, safe commands, and refuse any requests that fall outside this list.

Generated by OpenCVE AI on October 9, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Enmaso
Enmaso node-convert
Vendors & Products Enmaso
Enmaso node-convert

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.
Title @enmaso/node-convert through 1.0.0 OS Command Injection via filepath and convertTo
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Enmaso Node-convert
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T19:18:07.571Z

Reserved: 2026-10-08T16:52:24.549Z

Link: CVE-2026-107703

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T19:17:02.720

Modified: 2026-10-08T21:35:53.890

Link: CVE-2026-107703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T14:45:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')