Critical severity9.8NVD Advisory· Published Jun 1, 2018· Updated Jun 17, 2026
CVE-2018-3757
CVE-2018-3757
Description
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pdf-imagenpm | < 2.0.0 | 2.0.0 |
Affected products
2- cpe:2.3:a:pdf-image_project:pdf-image:2.0.0:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
5- github.com/roest01/node-pdf-image/commit/54679496a89738443917608c2bbe2f6e5dd20e83nvdPatchThird Party AdvisoryWEB
- hackerone.com/reports/340208nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5gwh-g79j-vh4qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-3757ghsaADVISORY
- www.npmjs.com/advisories/670ghsaWEB
News mentions
0No linked articles in our index yet.