Critical severity9.8NVD Advisory· Published Feb 28, 2020· Updated Jun 17, 2026
CVE-2020-8132
CVE-2020-8132
Description
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pdf-imagenpm | <= 2.0.0 | — |
Affected products
3- cpe:2.3:a:pdf-image_project:pdf-image:*:*:*:*:*:node.js:*:*Range: <=2.0.0
- pdf-image/pdf-imagedescription
Patches
Vulnerability mechanics
References
3- hackerone.com/reports/781664nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-rv7p-mmwq-x674ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-8132ghsaADVISORY
News mentions
0No linked articles in our index yet.