Executive brief
textract is a Node.js library used to extract text content from various document and image file formats (PDF, Word, Excel, images, etc.). A critical vulnerability allows attackers to execute arbitrary OS commands by crafting malicious filenames, potentially leading to complete system compromise or unauthorized access to sensitive data processed by applications using this library.
Technical details
textract through version 2.5.0 contains an OS command injection vulnerability (CWE-78, CWE-94) in multiple extractor modules (doc.js, rtf.js, dxf.js, images.js, and util.js). The vulnerability stems from inadequate sanitization of the filePath parameter, which is passed directly to child_process.exec() without proper escaping or validation. An attacker can craft a malicious filename containing shell metacharacters and command sequences that are interpreted by the underlying shell when the file is processed. No special privileges or authentication is required—any application using textract to process attacker-controlled files is vulnerable. Successful exploitation allows arbitrary command execution with the privileges of the process running textract, potentially leading to data exfiltration, system compromise, or denial of service.
Affected products
- textract textract through 2.5.0
Timeline
- 2026-03-25: disclosed: Vulnerability published to GitHub Advisory Database
- 2026-03-25: advisory: GHSA-9pcj-m5rr-p28g assigned; CVE-2026-26831 published