---
id: CVE-2026-85672
title: >-
  zerox 1.1.20 contains an OS command injection vulnerability in the file
  download mechanism where the temporary file extension derived from document
  URLs is interpolated unsanitized into shell commands executed by poppler
  utilities
summary: >-
  zerox 1.1.20 contains an OS command injection vulnerability in the file
  download mechanism where the temporary file extension derived from document
  URLs is interpolated unsanitized into shell commands executed by poppler
  utilities. Attac…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: getomni-ai
product: zerox
affected:
  - zerox <= 1.1.20
published: '2026-09-04'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:46.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85672'
references:
  - url: 'https://github.com/getomni-ai/zerox'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getomni-ai/zerox/blob/main/node-zerox/src/utils/file.ts'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getomni-ai/zerox/issues/206'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/zerox-1.1.20-os-command-injection-via-document-url-file-extension
    label: disclosure@vulncheck.com
  - url: 'https://github.com/getomni-ai/zerox/issues/206'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.01469
epssPercentile: 0.7263
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-08T17:05:26.052628Z'
ingestedAt: '2026-09-08T19:08:49.592Z'
---

## Overview

zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occurs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
