Headline
CVE-2020-28446: Snyk Vulnerability Database | Snyk
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications
snyk-id
SNYK-JS-NTESSERACT-1050982
published
26 Jan 2021
disclosed
14 Dec 2020
credit
JHU System Security Lab
How to fix?
Upgrade ntesseract to version 0.2.9 or higher.
Overview
ntesseract is a simple wrapper for the Tesseract OCR package for node.js
Affected versions of this package are vulnerable to Command Injection via lib/tesseract.js.
PoC:
var a =require("ntesseract");
a.process("& touch JHU #","",function(){})
Related news
GHSA-w868-4576-rv24: ntesseract vulnerable to Command Injection
The package ntesseract before 0.2.9 is vulnerable to Command Injection via lib/tesseract.js.