---
id: CVE-2026-107699
title: >-
  ppt2png through 0.0.6 contains an OS command injection vulnerability that
  allows attackers to execute operating system commands by supplying unsanitized
  input or output path arguments
summary: >-
  ppt2png through 0.0.6 contains an OS command injection vulnerability that
  allows attackers to execute operating system commands by supplying unsanitized
  input or output path arguments. Attackers can append shell metacharacters such
  as ';…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:35:53.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107699'
references:
  - url: 'https://gist.github.com/R3tro16/2daadc08b282c48d41203d1125d7632a'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/tzwm/ppt2png'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/tzwm/ppt2png/blob/8c68eba7af943de27422b12c6e224d28587af7ae/ppt2png.js#L5-L35
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ppt2png-through-0.0.6-os-command-injection-via-input-and-output-paths
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-08T20:06:22.187Z'
---

## Overview

ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
