CVE-2026-26830 | pdf-image up to 2.0.0 pdfFilePath os command injection
A vulnerability classified as critical has been found in pdf-image up to 2.0.0. This affects the function constructGetInfoCommand/constructConvertCommandForPage. Performing a manipulation of the argument pdfFilePath results in os command injection.
This vulnerability was named CVE-2026-26830. The attack may be initiated remotely. There is no available exploit.