dawnsparks-node-tesseract@0.4.0 vulnerabilities

A fork of a simple wrapper for the Tesseract OCR package

Direct Vulnerabilities

Known vulnerabilities in the dawnsparks-node-tesseract package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Arbitrary Code Execution

dawnsparks-node-tesseract is an A fork of a simple wrapper for the Tesseract OCR package

Affected versions of this package are vulnerable to Arbitrary Code Execution via the child_process function due to improper input sanitization.

To exploit this vulnerability, a user must submit an image file to a Node.js application that is using "dawnsparks-node-tesseract" as a dependency to perform optical character recognition. If the user's submitted image filename contains shell commands, those will be evaluated, allowing the user to execute arbitrary commands on the application's server.

How to fix Arbitrary Code Execution?

Upgrade dawnsparks-node-tesseract to version 0.4.1 or higher.

<0.4.1