CVE-2026-107703Critical· 9.8▾ Midnight@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters o…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37912High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37897Critical· 9.8There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211)
CVE-2025-11490Medium· 6.3A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13
CVE-2025-11491Medium· 6.3A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13
CVE-2025-11407Medium· 6.3A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1
CVE-2025-12296Medium· 4.7A security vulnerability has been detected in D-Link DAP-2695 2.00RC13