Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument Injection Handler. Performing a manipulation of the argument file_path results in argument injection. The attack may be initiated remotely. The patch is named db6e3f79d3beb20601be7e59669c39811ae3c330. It is recommended to apply a patch to fix this issue. | |
| Title | Fdawgs node-poppler Argument Injection index.js pdfUnite argument injection | |
| First Time appeared |
Fdawgs
Fdawgs node-poppler |
|
| Weaknesses | CWE-74 CWE-88 |
|
| CPEs | cpe:2.3:a:fdawgs:node-poppler:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fdawgs
Fdawgs node-poppler |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-25T04:45:11.359Z
Reserved: 2026-08-24T22:56:37.441Z
Link: CVE-2026-78637
No data.
Status : Received
Published: 2026-08-25T05:17:23.897
Modified: 2026-08-25T05:17:23.897
Link: CVE-2026-78637
No data.
OpenCVE Enrichment
No data.