Impact
@enmaso/node-convert through 1.0.0 contains an OS command injection flaw in convert.js. Unsanitized values supplied for the filepath and convertTo parameters are passed directly into a child_process.exec call that builds an ImageMagick command. An attacker can inject shell metacharacters or quote characters to terminate the intended command and execute arbitrary operating‑system commands with the privileges of the Node.js process. This provides full code‑execution capability and thus poses a severe confidentiality, integrity, and availability threat.
Affected Systems
All releases of @enmaso/node-convert up to and including 1.0.0 are affected. The security advisory lists no specific sub‑versions, but any distribution of the package whose version is 1.0.0 or earlier must be considered vulnerable. Users who still deploy the library in any form should treat the entire library as impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 9.3 classifies this vulnerability as Critical. With an EPSS score of 2%, the empirical likelihood of exploitation is low but nonzero, indicating that while widespread attacks have not been observed, the vulnerability could still be targeted. The attack vector is inferred to be remote, because the parameters that trigger the injection are exposed through API inputs that can be provided by untrusted users. An attacker who can influence these inputs, for example via an HTTP endpoint or a file upload mechanism, can therefore trigger the arbitrary command execution.
OpenCVE Enrichment