Executive brief
Fdawgs node-poppler is a Node.js wrapper for Poppler PDF rendering utilities used to convert and process PDF documents. A vulnerability in the argument handling code allows attackers to inject arbitrary command-line arguments into PDF processing commands, potentially leading to unauthorized file access, command execution, or service disruption when processing untrusted PDF inputs.
Technical details
An argument injection vulnerability exists in node-poppler's CLI argument handling code (src/index.js), affecting multiple PDF processing functions (pdfInfo, pdfToText, pdfToCairo, pdfToPpm, pdfImages, pdfToHtml, pdfToPs, pdfFonts, pdfDetach, pdfAttach, pdfSeparate, pdfUnite). The vulnerability occurs when the file_path argument is not properly sanitized before being passed to underlying Poppler utilities, allowing attackers to inject arbitrary command-line options. An attacker can remotely exploit this by providing specially crafted file paths that inject additional flags or commands. The fix (commit db6e3f79d3beb20601be7e59669c39811ae3c330) terminates option parsing with an end-of-options marker (`--`) before positional file paths, preventing argument injection.
Affected products
- Fdawgs node-poppler up to 9.1.2, 10.0.1
Timeline
- 2026-08-25: disclosed
- <UNKNOWN>: patched: Patch available as commit db6e3f79d3beb20601be7e59669c39811ae3c330