CVE-2026-78637
Severity CVSS v4.0:
MEDIUM
Type:
CWE-74
Injection
Publication date:
25/08/2026
Last modified:
25/08/2026
Description
A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Performing a manipulation of the argument file_path results in argument injection. The attack may be initiated remotely. The patch is named db6e3f79d3beb20601be7e59669c39811ae3c330. It is recommended to apply a patch to fix this issue.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/Fdawgs/node-poppler/
- https://github.com/Fdawgs/node-poppler/commit/db6e3f79d3beb20601be7e59669c39811ae3c330
- https://github.com/Fdawgs/node-poppler/issues/822
- https://github.com/Fdawgs/node-poppler/pull/842
- https://vuldb.com/cve/CVE-2026-78637
- https://vuldb.com/submit/886399
- https://vuldb.com/vuln/394864
- https://vuldb.com/vuln/394864/cti
- https://github.com/Fdawgs/node-poppler/issues/822



