Executive brief
npos-tesseract is a Node.js package that provides optical character recognition (OCR) functionality using the Tesseract engine. A command injection vulnerability in the OCR module allows an attacker to execute arbitrary system commands, potentially leading to complete system compromise, data theft, or service disruption.
Technical details
The vulnerability is a command injection flaw (CWE-77) located in lib/ocr.js at line 55 of the npos-tesseract package. The injection point occurs when user-controlled input is passed unsanitized to a system command, allowing an attacker to break out of the intended command and execute arbitrary shell commands. The vulnerability affects all versions up to and including 0.0.3. The attack vector is network-accessible (if the application is exposed over the network), requires no authentication or user interaction, and allows full system compromise including confidentiality, integrity, and availability impact.
Affected products
- npos-tesseract npos-tesseract 0.0.3 and earlier
Timeline
- 2022-08-03: disclosed
- 2022-08-02: advisory