Critical severity9.8NVD Advisory· Published Jul 28, 2022· Updated Jun 17, 2026
CVE-2016-4991
CVE-2016-4991
Description
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- nodepdf/nodepdfdescription
Patches
Vulnerability mechanics
References
1- lf.lc/cve/cve-2016-4991/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.