Vulnerabilities (CVE)

Filtered by vendor Zapolnoch Subscribe
Filtered by product Tesseract Ocr
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-26832 1 Zapolnoch 1 Tesseract Ocr 2026-06-05 N/A 9.8 CRITICAL
node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec() without proper sanitization