---
id: CVE-2026-107703
title: >-
  @enmaso/node-convert through 1.0.0 contains an OS command injection
  vulnerability in convert.js that allows attackers to execute shell commands
  via unsanitized filepath and convertTo arguments
summary: >-
  @enmaso/node-convert through 1.0.0 contains an OS command injection
  vulnerability in convert.js that allows attackers to execute shell commands
  via unsanitized filepath and convertTo arguments. Attackers can inject shell
  metacharacters o…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:35:53.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107703'
references:
  - url: 'https://gist.github.com/R3tro16/5a508fcfddfb0dfe66a0a53437ede74c'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/enmaso/node-convert'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/enmaso/node-convert/blob/143e4d76244e2daac57eef59d8ed5983e33ee4fb/convert.js#L4-L15
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/enmaso-node-convert-through-1.0.0-os-command-injection-via-filepath-and-convertto
    label: disclosure@vulncheck.com
  - url: 'https://gist.github.com/R3tro16/5a508fcfddfb0dfe66a0a53437ede74c'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
ingestedAt: '2026-10-08T20:06:22.188Z'
---

## Overview

@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
